Back

MEDIUM

An uncontrolled search path in the agent of Ivanti EPM before 2022 SU6, or the 2024 September update allows a local authenticated attacker with admin privileges to escalate their privileges to SYSTEM

Published Sep 10, 2024

Description

An uncontrolled search path in the agent of Ivanti EPM before 2022 SU6, or the 2024 September update allows a local authenticated attacker with admin privileges to escalate their privileges to SYSTEM.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (2)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner ivanti
Published Sep 10, 2024
Updated Sep 12, 2024
Reserved Sep 4, 2024

CISA Vulnrichment

Updated Sep 11, 2024

NVD

Status Analyzed
Modified Jun 17, 2026

Red Hat

No data

ENISA EUVD

Assigner ivanti
Published Sep 10, 2024
Updated Sep 12, 2024

GitHub

No data