This Metasploit module leverages an unauthenticated remote command execution vulnerability in Ivanti's EPM Agent Portal where an RPC client can invoke a method which will run an attacker-specified string on the remote target as NT AUTHORITY\SYSTEM. This vulnerability is present in versions prior to EPM 2021.1 Su4 and EPM 2022 Su2.
🛡️ VERIFIED CYBER INTELLIGENCE ID: #2426858
💾 Ivanti EPM Agent Portal Command Execution
⏱️ vor 612d 5h (21.11.2024 um 16:38 Uhr) 📂 💾 IT Security Tools 📡 Feed 🔗 Quelle: packetstormsecurity.com