SB2025031146 - Security restrictions bypass in Ivanti Neurons for MDM
Published: March 11, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Improper Check for Dropped Privileges (CVE-ID: N/A)
The vulnerability allows a remote user to bypass implemented security restrictions.
The vulnerability exists due to improper check for dropped privileges. A remote authenticated user with admin privileges to retain their session after privileges have been revoked.
Remediation
Install update from vendor's website.