Insecure deserialization in Ivanti Endpoint Manager allows a local authenticated attacker to escalate their privileges.
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
| Name | Vendor | Start Version | End Version | 
|---|---|---|---|
| Endpoint_manager | Ivanti | * | 2024 (excluding) | 
| Endpoint_manager | Ivanti | 2024 (including) | 2024 (including) | 
| Endpoint_manager | Ivanti | 2024-su1 (including) | 2024-su1 (including) | 
| Endpoint_manager | Ivanti | 2024-su2 (including) | 2024-su2 (including) | 
| Endpoint_manager | Ivanti | 2024-su3 (including) | 2024-su3 (including) | 
| Endpoint_manager | Ivanti | 2024-su3_security_release_1 (including) | 2024-su3_security_release_1 (including) |