CVE-2022-30121

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
23/09/2022
Last modified:
22/05/2025

Description

The “LANDesk(R) Management Agent” service exposes a socket and once connected, it is possible to launch commands only for signed executables. This is a security bug that allows a limited user to get escalated admin privileges on their system.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:ivanti:endpoint_manager:*:*:*:*:*:*:*:* 2021.1.1 (excluding)
cpe:2.3:a:ivanti:endpoint_manager:2021.1.1:-:*:*:*:*:*:*
cpe:2.3:a:ivanti:endpoint_manager:2021.1.1:su1:*:*:*:*:*:*
cpe:2.3:a:ivanti:endpoint_manager:2021.1.1:su2:*:*:*:*:*:*