ZeroHour

CVE-2024-34781

large

Authenticated SQL Injection to RCE in Ivanti Endpoint Manager

CVSS 3.1
7.2 high
EPSS
68%p99
Published
()
Modified
AI analysis

CVE-2024-34781 is a SQL injection flaw (CWE-89) in Ivanti Endpoint Manager (EPM), Ivanti's on-premises endpoint management platform. A remote attacker who is already authenticated with administrator privileges to EPM can send crafted input that is passed unsanitized to the backend database, enabling arbitrary SQL execution. On vulnerable builds the injection can be escalated from SQL injection to remote code execution on the EPM server (CVSS 3.1: 7.2 high, with high confidentiality, integrity, and availability impact). Affected organizations are those running EPM 2024 releases without the November 2024 Security Update, or EPM 2022 SU6 without the November 2024 update. No public proof-of-concept or confirmed in-the-wild exploitation is known yet, but the high EPSS score (68.5% probability of exploitation within 30 days, 99th percentile) indicates elevated exploitation risk.

What to do: Apply the November 2024 Security Update for Ivanti EPM 2024, or update EPM 2022 deployments to 2022 SU6 with the November 2024 Security Update, per Ivanti's advisory. Because exploitation requires administrator-level credentials, restrict and review privileged access to the EPM console/core server and monitor for suspicious database activity. Consult Ivanti's advisory for the exact patched build numbers for your release branch.

Affected
Ivanti Endpoint Manager (EPM) 2024all versions before the 2024 November Security Update
Ivanti Endpoint Manager (EPM) 2022 SU62022 SU6 before the November 2024 Security Update
Estimated exposure
largetens of thousands of on-premises EPM server deployments (estimate; each typically manages hundreds to thousands of endpoints) — Ivanti EPM is a widely deployed enterprise on-prem UEM platform, but no public active-install or internet-exposure counts are provided in this data, so the figure is an order-of-magnitude judgment based on Ivanti's enterprise customer base…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated attacker with admin privileges to achieve remote code execution.

Vendors
ivanti
Products
endpoint manager
Weakness
CWE-89
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.