CVE-2024-34779
largeAuthenticated SQL Injection to RCE in Ivanti Endpoint Manager (EPM)
CVE-2024-34779 is an SQL injection (CWE-89) in Ivanti Endpoint Manager (EPM) that allows a remote, authenticated attacker with administrator privileges to achieve remote code execution on the EPM server. It is triggered by sending crafted input to an unspecified vulnerable component of EPM while authenticated as an administrator, with the injected SQL escalating beyond data access to arbitrary code execution. An attacker who succeeds gains high-impact control (confidentiality, integrity, and availability) over the EPM core server, which centrally manages large fleets of corporate endpoints, potentially providing a foothold for broader compromise of managed devices. Organizations running EPM releases before 2022 SU6, or 2024 releases before the 2024 September update, are affected. No public proof-of-concept or confirmed in-the-wild exploitation is known yet, but the 24% EPSS score (98th percentile) indicates a comparatively high probability of exploitation within the next 30 days.
What to do: Upgrade to Ivanti EPM 2022 SU6, or apply the September 2024 update for the 2024 release. Restrict network access to the EPM core server and its web console, audit privileged accounts for signs of compromise, and prioritize patching any internet-exposed EPM servers. Given the elevated EPSS score, treat this patch as urgent even though no public exploit is yet known.
| Ivanti Endpoint Manager (EPM) | Versions before 2022 SU6, and 2024 releases before the 2024 September update |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution.
- Vendors
- ivanti
- Products
- endpoint manager
- Weakness
- CWE-89
- Vector
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H