A vulnerable upl/async_upload.asp web API endpoint in Ivanti LANDESK Management Suite (LDMS, aka Endpoint Manager) 10.0.1.168 Service Update 5 allows arbitrary file upload, which may lead to arbitrary remote code execution.
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
Link | Tags |
---|---|
https://www.gnzlabs.io/gnzlabs-blog/landesk-management-server-arbitrary-file-upload/ | third party advisory exploit |
https://www.gnzlabs.io/gnzlabs-blog/landesk-management-server-multiple-vulnerabilities/ | third party advisory |