VYPR
Medium severity6.7NVD Advisory· Published Sep 23, 2022· Updated Jun 17, 2026

CVE-2022-30121

CVE-2022-30121

Description

The “LANDesk(R) Management Agent” service exposes a socket and once connected, it is possible to launch commands only for signed executables. This is a security bug that allows a limited user to get escalated admin privileges on their system.

Affected products

7
  • cpe:2.3:a:ivanti:endpoint_manager:*:*:*:*:*:*:*:*+ 4 more
    • cpe:2.3:a:ivanti:endpoint_manager:*:*:*:*:*:*:*:*range: <2021.1.1
    • cpe:2.3:a:ivanti:endpoint_manager:2021.1.1:-:*:*:*:*:*:*
    • cpe:2.3:a:ivanti:endpoint_manager:2021.1.1:su1:*:*:*:*:*:*
    • cpe:2.3:a:ivanti:endpoint_manager:2021.1.1:su2:*:*:*:*:*:*
    • (no CPE)

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.