CVE-2020-12441: Ivanti Desktop&server Management
Critical severity, CVSS 9.8. EPSS: 3.8% chance of exploitation in the next 30 days.
Denial-of-Service (DoS) in Ivanti Service Manager HEAT Remote Control 7.4 due to a buffer overflow in the protocol parser of the ‘HEATRemoteService’ agent. The DoS can be triggered by sending a specially crafted network packet.
Affected products
- Ivanti Desktop&server Management: before 2020.1 (fixed in 2020.1)
- Ivanti Service Manager Heat Remote Control: version 7.4 only
Published 2020-08-06. Last modified 2026-06-17.