VDB

GCVE-110-NCSC-2025-318

GCVE-110-NCSC-2025-318
Advisory PublishedCVSS 7.8/10
Vulnetix · Advisory published October 15, 2025
Insecure deserialization in Ivanti Endpoint Manager allows a local authenticated attacker to escalate privileges.

Weaknesses (CWE)

CWE-502Deserialization of Untrusted DataCWE-22Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')CWE-89Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Risk Scores

CVSS 3.1
7.8/10
High · CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
Ivantivers:unknown/*

References

advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›