CVE Vulnerabilities

CVE-2022-30121

Published: Sep 23, 2022 | Modified: Oct 01, 2022
CVSS 3.x
6.7
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

The “LANDesk(R) Management Agent” service exposes a socket and once connected, it is possible to launch commands only for signed executables. This is a security bug that allows a limited user to get escalated admin privileges on their system.

Affected Software

Name Vendor Start Version End Version
Endpoint_manager Ivanti * 2021.1.1 (excluding)
Endpoint_manager Ivanti 2021.1.1 (including) 2021.1.1 (including)
Endpoint_manager Ivanti 2021.1.1-su1 (including) 2021.1.1-su1 (including)
Endpoint_manager Ivanti 2021.1.1-su2 (including) 2021.1.1-su2 (including)

References