CVE-2024-7612

CVSS 3.1 Score 7.8 of 10 (high)

Details

Published Oct 8, 2024
Updated: Dec 18, 2024
CWE ID 732

Summary

CVE-2024-7612 is a newly disclosed cybersecurity vulnerability affecting Ivanti Endpoint Management Manager (EPMM) versions prior to 12.1.0.4. This issue arises from insecure permissions, enabling a local authenticated attacker to manipulate sensitive application components. The attacker can potentially exploit this vulnerability to gain unauthorized control or access to critical system functionalities, posing a significant risk to organizational security. It is essential that Ivanti EPMM users upgrade to the latest version to mitigate this threat and maintain the security of their systems.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Ivanti Endpoint Manager Mobile

Affected Vendors

  • Ivanti