Ivanti Endpoint Manager Remote Code Execution

HIGH (8.8)

Threat Intelligence

Low Risk
EPSS Score: 0.27% chance of exploitation (percentile: 51%)
🔍 Detection Tools: None available in major open-source tools
⚔️ Exploit Availability: No public exploits found

How we test →

What is it?

Ivanti Endpoint Manager is a software tool used to manage and secure endpoint devices. This vulnerability allows attackers to execute arbitrary code on the server by writing files, potentially leading to remote code execution.

Am I affected?

You're affected if you use Improper control of dynamically managed code resources. Affected versions: 2024 If you don't recognise this software, you're probably not affected.

How to fix

Upgrade to Ivanti Endpoint Manager 2024 SU4 SR1 or later.
- Immediate mitigations:
* Restrict network access to your Ivanti Endpoint Manager instance (firewall it from the public internet)
* Audit admin account activity for suspicious access patterns
* Monitor for unauthorized file creation

References