ZeroHour

CVE-2024-34783

large

Authenticated SQL Injection Leading to RCE in Ivanti Endpoint Manager

CVSS 3.1
7.2 high
EPSS
43%p99
Published
()
Modified
AI analysis

CVE-2024-34783 is a SQL injection flaw (CWE-89) in Ivanti Endpoint Manager (EPM) that can be exploited by a remote, authenticated attacker holding administrator privileges, ultimately achieving remote code execution on the EPM core server. Because it requires network access plus high-level (admin) credentials, exploitation depends on an attacker first obtaining or compromising an administrator account, for example via credential theft or phishing. An attacker who succeeds gains full confidentiality, integrity, and availability impact on the server, and from an EPM core server can typically pivot to managed endpoints across the enterprise. Organizations running Ivanti EPM on versions before the 2022 SU6 release, or on 2024 versions without the September 2024 update, are affected. No public proof-of-concept, KEV listing, or confirmed in-the-wild exploitation is known yet, but the EPSS score of 43.4% (99th percentile) indicates a materially elevated likelihood of exploitation within 30 days.

What to do: Upgrade EPM core servers to the 2022 SU6 release (2022 branch) or apply the September 2024 update (2024 branch) as soon as possible. In the interim, restrict network access to the EPM core server and its web/agent ports to trusted management segments, review administrator accounts for unusual or compromised credentials, and monitor EPM server logs for suspicious SQL or command-execution activity given the elevated EPSS score.

Affected
Ivanti Endpoint Manager (EPM)2022 versions prior to 2022 SU6; 2024 versions prior to the September 2024 update
Estimated exposure
largetens of thousands of EPM core-server deployments, each typically managing hundreds to thousands of endpoints (on the order of 10k-100k vulnerable servers) — Ivanti EPM (formerly LANDESK) is deployed as one or a few core servers per organization across Ivanti's large enterprise customer base, so the vulnerable-system count is on the order of tens of thousands of core servers while endpoint…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution.

Vendors
ivanti
Products
endpoint manager
Weakness
CWE-89
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

In the news