Remote Code Execution via Unsafe Deserialization in Ivanti Endpoint Manager 2022 su3 and earlier versions

Remote Code Execution via Unsafe Deserialization in Ivanti Endpoint Manager 2022 su3 and earlier versions

CVE-2023-35084 · CRITICAL Severity

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Unsafe Deserialization of User Input could lead to Execution of Unauthorized Operations in Ivanti Endpoint Manager 2022 su3 and all previous versions, which could allow an attacker to execute commands remotely.

Learn more about our User Device Pen Test.