Insecure default permissions in the agent of Ivanti Endpoint Manager before version 2024 SU4 allows a local authenticated attacker to write arbitrary files anywhere on disk
During installation, installed file permissions are set to allow anyone to modify those files.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Endpoint_manager | Ivanti | * | 2024 (excluding) |
| Endpoint_manager | Ivanti | 2024 (including) | 2024 (including) |
| Endpoint_manager | Ivanti | 2024-su1 (including) | 2024-su1 (including) |
| Endpoint_manager | Ivanti | 2024-su2 (including) | 2024-su2 (including) |
| Endpoint_manager | Ivanti | 2024-su3 (including) | 2024-su3 (including) |
| Endpoint_manager | Ivanti | 2024-su3_security_release_1 (including) | 2024-su3_security_release_1 (including) |