7.8
/ 10
HIGH
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Description
Insecure deserialization in Ivanti Endpoint Manager allows a local authenticated attacker to escalate their privileges.
Basic Information
ID
CVE-2025-11622
Source
ivanti
Published
Oct 13, 2025 at 21:07
Affected Product
Vendor
Ivanti
Product
Endpoint Manager
Version
2024 SU3 SR1
Affected Versions
Ivanti Endpoint Manager 2024 SU3 SR1
Ivanti Endpoint Manager 2022 SU8 SR2
Ivanti Endpoint Manager 2022 SU8 SR2