CVE-2024-22026
A local privilege escalation vulnerability in EPMM before 12.1.0.0 allows an authenticated local user to bypass shell restriction and execute arbitrary commands on the appliance.
- Affected products
- Ivanti Epm
- Ivanti Endpoint Manager Mobile
- < 12.1.0.0
- Fix
- Available
- CVSS 3.1
- 6.7 MEDIUM
- EPSS
- 1.1% (64th percentile)
- Weakness
- CWE-284
- NVD status
- Modified
- Published
- 2024-05-22
CVE-2024-22026 at NVD
2 known exploits for CVE-2024-22026
Proof-of-concept code and exploit modules indexed by Sploitus