Skip to content

Ivanti Endpoint Manager Vulnerability - 20230626003

Overview

Remote Code Execution in Ivanti Endpoint Manager (EPM) 2022 Su3 and all prior versions allows an unauthenticated user to elevate rights. This exploit could potentially be used in conjunction with other OS (Operating System) vulnerabilities to escalate privileges on the machine or be used as a stepping stone to pivot to other network-attached machines.

What is the vulnerability?

CVE-2023-28323 - CVSS v3 Base Score: 9.36

What is vulnerable?

The vulnerability affects the following products:

  • Ivanti Endpoint Manager prior to and including EPM 2022 SU3 (EPM 2022 - EOF May 2023).

What has been observed?

There is no evidence of exploitation affecting Western Australian Government networks at the time of publishing.

Recommendation

The WA SOC recommends administrators apply the updates and recommendations as per vendor instructions to all affected devices: