Impact
The flaw is a missing authorization check in Ivanti Endpoint Manager Mobile that enables a remote authenticated attacker to raise their privileges to administrator. This elevates the attacker’s control over the device, allowing full configuration changes, installation of additional software, and potential compromise of confidential data. The weakness is a classic access control violation.
Affected Systems
Ivanti Endpoint Manager Mobile versions before 12.10.0.0, 12.9.0.2, and 12.8.0.4 are affected. The vulnerability exists in the vendor product’s native mobile management component.
Risk and Exploitability
The CVSS score of 8.8 marks the vulnerability as High, and the EPSS score of 1% indicates a low but non‑zero likelihood of exploitation. The flaw is not listed in the CISA KEV catalog, implying no known widespread attacks yet, but the attack vector is inferred to be remote after initial authentication. An attacker would need only to authenticate as a lower‑privilege user and then call privileged API endpoints that lack proper checks, subsequently assuming administrative rights.
OpenCVE Enrichment