Ivanti EPM Agent Portal Command Execution

Discussion in 'News Aggregator' started by Packet Storm, 22 Nov 2024.

  1. Packet Storm

    Packet Storm Guest

    This Metasploit module leverages an unauthenticated remote command execution vulnerability in Ivanti's EPM Agent Portal where an RPC client can invoke a method which will run an attacker-specified string on the remote target as NT AUTHORITY\SYSTEM. This vulnerability is present in versions prior to EPM 2021.1 Su4 and EPM 2022 Su2.

    Continue reading...
     

Share This Page

Loading...