CVE-2024-34781
largeAuthenticated SQL Injection to RCE in Ivanti Endpoint Manager
CVE-2024-34781 is a SQL injection flaw (CWE-89) in Ivanti Endpoint Manager (EPM), Ivanti's on-premises endpoint management platform. A remote attacker who is already authenticated with administrator privileges to EPM can send crafted input that is passed unsanitized to the backend database, enabling arbitrary SQL execution. On vulnerable builds the injection can be escalated from SQL injection to remote code execution on the EPM server (CVSS 3.1: 7.2 high, with high confidentiality, integrity, and availability impact). Affected organizations are those running EPM 2024 releases without the November 2024 Security Update, or EPM 2022 SU6 without the November 2024 update. No public proof-of-concept or confirmed in-the-wild exploitation is known yet, but the high EPSS score (68.5% probability of exploitation within 30 days, 99th percentile) indicates elevated exploitation risk.
What to do: Apply the November 2024 Security Update for Ivanti EPM 2024, or update EPM 2022 deployments to 2022 SU6 with the November 2024 Security Update, per Ivanti's advisory. Because exploitation requires administrator-level credentials, restrict and review privileged access to the EPM console/core server and monitor for suspicious database activity. Consult Ivanti's advisory for the exact patched build numbers for your release branch.
| Ivanti Endpoint Manager (EPM) 2024 | all versions before the 2024 November Security Update |
| Ivanti Endpoint Manager (EPM) 2022 SU6 | 2022 SU6 before the November 2024 Security Update |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated attacker with admin privileges to achieve remote code execution.
- Vendors
- ivanti
- Products
- endpoint manager
- Weakness
- CWE-89
- Vector
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.