important · Privilege — EPMM
An ordinary authenticated Ivanti EPMM user can promote themselves to administrator.
Affects
Ivanti Endpoint Manager Mobile, an enterprise mobile-device-management server for iOS, Android, macOS and Windows fleets.
A low-privilege user with network access can invoke an undisclosed operation whose missing authorization check grants EPMM administrator authority.
Detail and 2 sources
The vulnerable request or endpoint and a working proof of concept are not public.
Fixed EPMM release lines have been published.