The “LANDesk(R) Management Agent” service exposes a socket and once connected, it is possible to launch commands only for signed executables. This is a security bug that allows a limited user to get escalated admin privileges on their system.
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.