Ivanti: Endpoint Manager 2021 device management software vulnerable

Attackers can execute malicious code with elevated rights. Admins must upgrade Ivanti EPM to a version that is still supported.

Save to Pocket listen Print view
Finger drückt auf Knopf

(Image: Photon photo/Shutterstock.com)

1 min. read
This article was originally published in German and has been automatically translated.

Ivanti's Endpoint Manager (EPM) device management software is vulnerable in the 2021 release. However, support for it has expired and there are no more security updates. To secure systems, admins need to upgrade.

In a warning message, the developers state that the vulnerability (CVE-2024-22058"high") only threatens all EPM versions up to and including 2021.1 SU5. Admins must therefore upgrade to EPM 2022 to prevent attacks. These editions do not include the vulnerable legacy Remote Control component.

If the upgrade is not carried out, local attackers can execute malicious code with elevated rights on PCs with EPM Agent installed. Ivanti assures that they have not observed any attacks so far.

(des)