CVE-2024-32845
largeAuthenticated Admin SQL Injection to RCE in Ivanti Endpoint Manager
Ivanti Endpoint Manager (EPM) contains a SQL injection flaw (CWE-89) that a remote attacker holding administrator-level credentials can exploit to achieve remote code execution on the EPM server. The flaw is reachable over the network (AV:N) but requires high privileges (PR:H), so only authenticated EPM administrators can trigger it; successful exploitation yields high impact on confidentiality, integrity, and availability of the affected system. Affected products are EPM 2022 releases before Service Update 6 (SU6) and EPM 2024 releases before the September 2024 update. There is currently no public proof-of-concept and the flaw is not in CISA's KEV catalog, but its elevated EPSS score (24% probability of exploitation within 30 days, 98th percentile) indicates a meaningful likelihood of exploitation in the near term.
What to do: Upgrade EPM 2022 deployments to Service Update 6 and EPM 2024 deployments to the September 2024 update. In the interim, audit and restrict accounts with EPM administrator privileges and limit network access to the EPM core server and its database, since admin credentials are required to exploit. Given the elevated EPSS score, prioritize patching and monitor Ivanti advisories for indicators of compromise.
| Ivanti Endpoint Manager (EPM) | 2022 before Service Update 6 (SU6); 2024 before the September 2024 update |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution.
- Vendors
- ivanti
- Products
- endpoint manager
- Weakness
- CWE-89
- Vector
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H