ZeroHour

CVE-2024-32845

large

Authenticated Admin SQL Injection to RCE in Ivanti Endpoint Manager

CVSS 3.1
7.2 high
EPSS
24%p98
Published
()
Modified
AI analysis

Ivanti Endpoint Manager (EPM) contains a SQL injection flaw (CWE-89) that a remote attacker holding administrator-level credentials can exploit to achieve remote code execution on the EPM server. The flaw is reachable over the network (AV:N) but requires high privileges (PR:H), so only authenticated EPM administrators can trigger it; successful exploitation yields high impact on confidentiality, integrity, and availability of the affected system. Affected products are EPM 2022 releases before Service Update 6 (SU6) and EPM 2024 releases before the September 2024 update. There is currently no public proof-of-concept and the flaw is not in CISA's KEV catalog, but its elevated EPSS score (24% probability of exploitation within 30 days, 98th percentile) indicates a meaningful likelihood of exploitation in the near term.

What to do: Upgrade EPM 2022 deployments to Service Update 6 and EPM 2024 deployments to the September 2024 update. In the interim, audit and restrict accounts with EPM administrator privileges and limit network access to the EPM core server and its database, since admin credentials are required to exploit. Given the elevated EPSS score, prioritize patching and monitor Ivanti advisories for indicators of compromise.

Affected
Ivanti Endpoint Manager (EPM)2022 before Service Update 6 (SU6); 2024 before the September 2024 update
Estimated exposure
largetens of thousands of EPM core server deployments worldwide (estimate) — Ivanti EPM is a decades-old enterprise endpoint-management platform widely deployed by large organizations, implying an order of tens of thousands of vulnerable EPM servers prior to patching, though most are internal and only some are…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution.

Vendors
ivanti
Products
endpoint manager
Weakness
CWE-89
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

In the news