Advisory Details

October 7th, 2025

(0Day) Ivanti Endpoint Manager AgentPortal Deserialization of Untrusted Data Local Privilege Escalation Vulnerability

ZDI-25-947
ZDI-CAN-25369

CVE ID
CVSS SCORE 7.8, AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
AFFECTED VENDORS Ivanti
AFFECTED PRODUCTS Endpoint Manager
VULNERABILITY DETAILS

This vulnerability allows local attackers to escalate privileges on affected installations of Ivanti Endpoint Manager. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.

The specific flaw exists within the AgentPortal service. The issue results from the lack of proper validation of user-supplied data, which can result in deserialization of untrusted data. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of SYSTEM.

ADDITIONAL DETAILS

11/05/24 – ZDI reported the vulnerability to the vendor
11/08/24 – the vendor acknowledged the receipt of the report
01/24/25 – the vendor confirmed the issue and requested an extension until the second half of 2025
05/06/25 – ZDI asked for updates
07/29/25 - the vendor communicated that the issue will be patched in November 2025
09/30/25 - ZDI notified the vendor of the intention to publish the case as a 0-day advisory

-- Mitigation: Given the nature of the vulnerability, the only salient mitigation strategy is to restrict interaction with the product.


DISCLOSURE TIMELINE
  • 2024-11-05 - Vulnerability reported to vendor
  • 2025-10-07 - Coordinated public release of advisory
  • 2025-10-07 - Advisory Updated
CREDIT 06fe5fd2bc53027c4a3b7e395af0b850e7b8a044
BACK TO ADVISORIES