ZeroHour

CVE-2024-32840

large

Authenticated SQL Injection Leading to RCE in Ivanti Endpoint Manager

CVSS 3.1
7.2 high
EPSS
25%p98
Published
()
Modified
AI analysis

CVE-2024-32840 is an SQL injection vulnerability (CWE-89) in Ivanti Endpoint Manager (EPM) that allows a remote, authenticated attacker with administrator privileges to achieve remote code execution on the EPM server. It is triggered when crafted input reaches a vulnerable database query over the network; no user interaction is required, but the attacker must already hold admin-level credentials. Successful exploitation yields high-impact compromise of the server (confidentiality, integrity and availability all rated high), giving the attacker code execution on the EPM core server. Organizations running EPM 2022 before Service Update 6, or EPM 2024 before the September 2024 update, are affected. There is no confirmed exploitation, no public proof-of-concept, and the flaw is not in CISA KEV, but its EPSS score of 25.4% (98th percentile) indicates an elevated probability of exploitation within the next 30 days.

What to do: Upgrade EPM 2022 deployments to 2022 SU6 or later, and EPM 2024 deployments to the September 2024 (or later) update, per Ivanti's urgent advisory. Until patched, restrict network access to the EPM web console/core server, keep the EPM administrator population to a minimum since the flaw requires admin credentials, and review logs for anomalous admin activity. Given the elevated EPSS score, prioritize this patch promptly even though it is not yet on CISA KEV.

Affected
Ivanti Endpoint Manager (EPM)2022 versions before 2022 SU6; 2024 versions before the September 2024 update
Estimated exposure
largetens of thousands of on-prem EPM core-server deployments (subset internet-exposed; exact counts not published) — Ivanti EPM is a long-standing enterprise endpoint-management suite typically deployed as one core server per organization, which supports an order-of-magnitude estimate of tens of thousands of deployments, though no public install counts…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution.

Vendors
ivanti
Products
endpoint manager
Weakness
CWE-89
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

In the news