CVE-2025-22464

CVSS 3.1 Score 6.1 of 10 (medium)

Details

Published Apr 8, 2025
CWE ID 822

Summary

CVE-2025-22464 is a vulnerability affecting Ivanti Endpoint Manager versions prior to 2024 SU1 and 2022 SU7. An attacker with local access can exploit this untrusted pointer dereference flaw to write arbitrary data into memory, leading to a denial-of-service condition. This issue poses a threat as it allows an attacker to manipulate the system's memory, potentially disrupting its functionality. Ivanti Endpoint Manager users are advised to upgrade to a patched version to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Ivanti Endpoint Manager

Affected Vendors

  • Ivanti