CVE-2025-22464

Published Apr 8, 2025

Last updated a month ago

Overview

Description
An untrusted pointer dereference vulnerability in Ivanti Endpoint Manager before version 2024 SU1 or before version 2022 SU7 allows an attacker with local access to write arbitrary data into memory causing a denial-of-service condition.
Source
3c1d8aa1-5a33-4ea4-8992-aadd6440af75
NVD status
Analyzed

Risk scores

CVSS 3.1

Type
Primary
Base score
6.1
Impact score
4.2
Exploitability score
1.8
Vector string
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H
Severity
MEDIUM

Weaknesses

3c1d8aa1-5a33-4ea4-8992-aadd6440af75
CWE-822
nvd@nist.gov
NVD-CWE-Other

Social media

Hype score
Not currently trending

Configurations