← Back

CVE-2022-30121

nvd nist
Published: Sep 23, 2022Modified: May 22, 2025

JSON object

Loading...
6.7
Vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Exploitability: 0.8 / Impact: 5.9
Source: NVD

Description

The “LANDesk(R) Management Agent” service exposes a socket and once connected, it is possible to launch commands only for signed executables. This is a security bug that allows a limited user to get escalated admin privileges on their system.

Affected (4)

1 product
Endpoint Manager
Configuration A
4 vulnerable
Vulnerable SoftwareAffected Versions
Ivanti
Before 2021.1.1
Version 2021.1.1
Version 2021.1.1 su1
Version 2021.1.1 su2

Timeline

No history available yet.