logo

Multiple Vulnerabilities in Ivanti Endpoint Manager Could Allow for Remote Code Execution

ID: 3dcc40d9-81a6-544b-a197-1c88063b3c7a

STIX ID: report--3dcc40d9-81a6-544b-a197-1c88063b3c7a

Feed Name: CISecurity.org Advisories

Threat Score
70/100

Date Published: 2025-04-08

Date Updated: 2026-04-27

...
...

Multiple vulnerabilities in Ivanti Endpoint Manager (versions before 2024 SU1 and before 2022 SU7), including reflected XSS (CVE-2025-22465, CVE-2025-22466), DLL hijacking (CVE-2025-22458), and SQL injection (CVE-2025-22461), could allow remote code execution, privilege escalation to SYSTEM, denial-of-service, and limited interception of traffic; successful exploitation could let an attacker install programs and view, change, or delete data.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.