ZeroHour

CVE-2024-34785

large

Authenticated SQL Injection Leading to RCE in Ivanti Endpoint Manager (EPM)

CVSS 3.1
7.2 high
EPSS
25%p98
Published
()
Modified
AI analysis

CVE-2024-34785 is a SQL injection flaw (CWE-89) in Ivanti Endpoint Manager (EPM) that can be exploited remotely by an authenticated attacker holding admin-level privileges. It is triggered by attacker-controlled input processed by the EPM backend database in a request made with administrative credentials. Successful exploitation escalates from the database to arbitrary code execution on the EPM server, giving the attacker control of the management platform and, transitively, the endpoints it manages. Affected deployments are Ivanti EPM 2022 before SU6 and EPM 2024 before the September 2024 update. There is no known in-the-wild exploitation or public proof-of-concept yet, but the 25.4% EPSS score (98th percentile) signals a significant probability of exploitation within the next 30 days.

What to do: Upgrade EPM 2022 to SU6 and EPM 2024 to the September 2024 update, since the flaw is fixed in both release streams. Because exploitation requires admin privileges on the EPM console/API, inventory which accounts hold EPM administrator rights, rotate any credentials that could be compromised, and keep EPM core servers off the public internet where possible. Monitor EPM servers for anomalous database or process activity as a precaution given the elevated EPSS likelihood.

Affected
Ivanti Endpoint Manager (EPM) 2022all versions prior to the 2022 SU6 release
Ivanti Endpoint Manager (EPM) 2024all versions prior to the September 2024 update
Estimated exposure
largeroughly tens of thousands of EPM core-server deployments across enterprise IT estates (managed endpoints plausibly in the millions) — Ivanti EPM (formerly LANDesk) is a mainstream enterprise endpoint-management platform with deployments across tens of thousands of organizations, so the vulnerable server installations are estimated at the 10k–100k order from known…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution.

Vendors
ivanti
Products
endpoint manager
Weakness
CWE-89
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

In the news