The “LANDesk(R) Management Agent” service exposes a socket and once connected, it is possible to launch commands only for signed executables. This is a security bug that allows a limited user to get escalated admin privileges on their system.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Endpoint_manager | Ivanti | * | 2021.1.1 (excluding) |
Endpoint_manager | Ivanti | 2021.1.1 (including) | 2021.1.1 (including) |
Endpoint_manager | Ivanti | 2021.1.1-su1 (including) | 2021.1.1-su1 (including) |
Endpoint_manager | Ivanti | 2021.1.1-su2 (including) | 2021.1.1-su2 (including) |