ZeroHour

CVE-2024-13162

large

Authenticated SQL Injection to RCE in Ivanti Endpoint Manager (EPM)

CVSS 3.1
7.2 high
EPSS
64%p99
Published
()
Modified
AI analysis

CVE-2024-13162 is a SQL injection (CWE-89) in Ivanti Endpoint Manager (EPM) that completes fixes left incomplete by the earlier patch for CVE-2024-32848. A remote attacker who already holds administrator credentials on the EPM deployment can send crafted input to the database layer over the network (AV:N, low complexity, high privileges required), triggering the injection. Successful exploitation escalates to arbitrary remote code execution on the EPM server, with high impact to confidentiality, integrity, and availability. Organizations running EPM 2024 or EPM 2022 SU6 without the January 2025 Security Update are affected. No public proof-of-concept or CISA KEV listing is known yet, but the flaw sits in the 99th EPSS percentile with a 64.2% predicted probability of exploitation within 30 days, so it is considered very likely to be attacked soon.

What to do: Apply the January-2025 Security Update for EPM 2024 and the January-2025 Security Update for EPM 2022 SU6, and confirm systems that already took earlier updates for CVE-2024-32848 also receive this January-2025 rollup, since it completes the incomplete prior fix. Restrict administrative access to the EPM core server and console, and review privileged accounts for signs of compromise given the high predicted exploitation likelihood.

Affected
Ivanti Endpoint Manager (EPM) 2024All versions prior to the EPM 2024 January-2025 Security Update
Ivanti Endpoint Manager (EPM) 2022 SU6All versions prior to the EPM 2022 SU6 January-2025 Security Update
Estimated exposure
large≈ tens of thousands of on-prem EPM core-server deployments (est.; no public install-count telemetry) — Ivanti EPM (LANDesk lineage) is a long-established on-prem enterprise management product typically deployed as one vulnerable core server per organization, so the estimate reflects an order-of-magnitude assumption of a mid-to-large…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

SQL injection in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote authenticated attacker with admin privileges to achieve remote code execution. This CVE addresses incomplete fixes from CVE-2024-32848.

Vendors
ivanti
Products
endpoint manager
Weakness
CWE-89
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.