The “LANDesk(R) Management Agent” service exposes a socket and once connected, it is possible to launch commands only for signed executables. This is a security bug that allows a limited user to get escalated admin privileges on their system.
2022-09-23T14:15:12.273
2025-05-22T21:15:22.567
Modified
CVSSv3.1: 6.7 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | ivanti | endpoint_manager | < 2021.1.1 | Yes |
Application | ivanti | endpoint_manager | 2021.1.1 | Yes |
Application | ivanti | endpoint_manager | 2021.1.1 | Yes |
Application | ivanti | endpoint_manager | 2021.1.1 | Yes |