ZeroHour

CVE-2024-29847

large

Unauthenticated Deserialization RCE in Ivanti Endpoint Manager Agent Portal

CVSS 3.1
9.8 critical
EPSS
53%p99
Published
()
Modified
AI analysis

CVE-2024-29847 is a deserialization of untrusted data flaw (CWE-502) in the agent portal of Ivanti Endpoint Manager (EPM). A remote, unauthenticated attacker can send maliciously crafted serialized data to the agent portal, and processing of that input results in remote code execution on the EPM server. Because EPM core servers typically hold privileged roles in enterprise Windows environments, successful exploitation could provide a foothold for broader network compromise. Organizations running EPM before the 2022 SU6 release, or before the 2024 September update, are affected. The flaw was patched in September 2024 with no public PoC or confirmed in-the-wild exploitation yet, but its high EPSS (52.9%, 99th percentile) suggests exploitation is likely within 30 days, and it arrives amid separate active exploitation of other Ivanti products (the Cloud Service Appliance), raising attacker interest in Ivanti software generally.

What to do: Upgrade to Ivanti EPM 2022 SU6 if on the 2022 release line, or apply the September 2024 update if on the 2024 line. Restrict network access to the EPM agent portal to trusted management segments and review EPM servers for signs of compromise given the current attention on Ivanti products. Review Ivanti's September 2024 EPM advisory for additional vulnerabilities fixed at the same time.

Affected
Ivanti Endpoint Manager (EPM) - agent portalAll versions before 2022 SU6
Ivanti Endpoint Manager (EPM) - agent portalAll 2024-line versions before the September 2024 update
Estimated exposure
largetens of thousands of enterprise EPM deployments (internet-exposed footprint likely smaller) — Ivanti EPM, the former LANDESK Management Suite, is widely deployed by enterprise IT organizations, but the agent portal typically sits on internal management networks rather than the public internet, so the number of directly exposed…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Deserialization of untrusted data in the agent portal of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote unauthenticated attacker to achieve remote code execution.

Vendors
ivanti
Products
endpoint manager
Weakness
CWE-502
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news