ZeroHour

CVE-2024-50326

large

Admin-Authenticated SQL Injection to RCE in Ivanti Endpoint Manager

CVSS 3.1
7.2 high
EPSS
26%p98
Published
()
Modified
AI analysis

Ivanti Endpoint Manager (EPM) contains a SQL injection vulnerability (CWE-89) that can be triggered by a remote attacker who holds administrative credentials for the product. By sending crafted SQL through an authenticated administrative interface, the attacker can execute arbitrary SQL against the EPM database backend, which ultimately yields remote code execution on the EPM server. A successful attack carries high impact to confidentiality, integrity, and availability of the server, effectively enabling full compromise of the management infrastructure. Organizations running EPM releases before the 2024 November Security Update, or before the 2022 SU6 November Security Update on the legacy branch, are affected. There are no known public proofs of concept or confirmed in-the-wild exploitation yet, but the elevated EPSS score (26.5%, 98th percentile) indicates a relatively high likelihood of exploitation within the next 30 days.

What to do: Apply the November 2024 Security Update on the EPM 2024 branch or the 2022 SU6 November Security Update on the EPM 2022 branch, treating this as a near-term priority given the elevated EPSS score. Until patched, restrict and audit administrative access to the EPM console and review admin accounts for anomalous activity. Check your installed EPM release/update level against the two named update packages to confirm whether you are in an affected range.

Affected
Ivanti Endpoint ManagerBefore the 2024 November Security Update (EPM 2024 branch); or before the 2022 SU6 November Security Update (legacy EPM 2022 branch)
Estimated exposure
largeplausibly tens of thousands of enterprise core-server deployments (internal management servers, not typically internet-exposed) — Ivanti EPM (formerly LANDESK) is a long-established enterprise endpoint-management platform with an installed base likely in the tens of thousands of core servers across organizations; because its admin interfaces are usually…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated attacker with admin privileges to achieve remote code execution.

Vendors
ivanti
Products
endpoint manager
Weakness
CWE-89
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.