🕳️ Vulnerabilities & CVEs

Ivanti Avalanche's Sneaky Priv-Esc Hole: No Auth Needed, Local Root Awaits

Ivanti swore their Avalanche MDM was battle-tested. Then CVE-2022-43554 drops: a missing auth check letting locals climb to root. Who's surprised? Not me.

Diagram showing privilege escalation attack path in Ivanti Avalanche Smart Device Service

⚡ Key Takeaways

  • CVE-2022-43554 enables unauthenticated local privilege escalation in Ivanti Avalanche Smart Device Service—patch immediately if on vulnerable versions. 𝕏
  • Affects Windows agents primarily; high CVSS 7.8 score means serious risk for enterprise device management fleets. 𝕏
  • Ivanti's acquisition-heavy history likely behind recurring auth slips—demand better from your MDM vendor. 𝕏
Published by

theAIcatchup

Threat intelligence. Zero noise.

Worth sharing?

Get the best Cybersecurity stories of the week in your inbox — no noise, no spam.

Originally reported by NVD Vulnerabilities

Stay in the loop

The week's most important stories from theAIcatchup, delivered once a week.