ZeroHour

CVE-2024-34779

large

Authenticated SQL Injection to RCE in Ivanti Endpoint Manager (EPM)

CVSS 3.1
7.2 high
EPSS
24%p98
Published
()
Modified
AI analysis

CVE-2024-34779 is an SQL injection (CWE-89) in Ivanti Endpoint Manager (EPM) that allows a remote, authenticated attacker with administrator privileges to achieve remote code execution on the EPM server. It is triggered by sending crafted input to an unspecified vulnerable component of EPM while authenticated as an administrator, with the injected SQL escalating beyond data access to arbitrary code execution. An attacker who succeeds gains high-impact control (confidentiality, integrity, and availability) over the EPM core server, which centrally manages large fleets of corporate endpoints, potentially providing a foothold for broader compromise of managed devices. Organizations running EPM releases before 2022 SU6, or 2024 releases before the 2024 September update, are affected. No public proof-of-concept or confirmed in-the-wild exploitation is known yet, but the 24% EPSS score (98th percentile) indicates a comparatively high probability of exploitation within the next 30 days.

What to do: Upgrade to Ivanti EPM 2022 SU6, or apply the September 2024 update for the 2024 release. Restrict network access to the EPM core server and its web console, audit privileged accounts for signs of compromise, and prioritize patching any internet-exposed EPM servers. Given the elevated EPSS score, treat this patch as urgent even though no public exploit is yet known.

Affected
Ivanti Endpoint Manager (EPM)Versions before 2022 SU6, and 2024 releases before the 2024 September update
Estimated exposure
largetens of thousands of EPM core-server deployments worldwide, with only a subset internet-exposed — Ivanti EPM (formerly LANDesk) is a long-standing enterprise endpoint-management platform typically deployed as one core server per organization, implying an install base in the tens of thousands, though most core servers sit on internal…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution.

Vendors
ivanti
Products
endpoint manager
Weakness
CWE-89
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

In the news