CVE-2024-50326
largeAdmin-Authenticated SQL Injection to RCE in Ivanti Endpoint Manager
Ivanti Endpoint Manager (EPM) contains a SQL injection vulnerability (CWE-89) that can be triggered by a remote attacker who holds administrative credentials for the product. By sending crafted SQL through an authenticated administrative interface, the attacker can execute arbitrary SQL against the EPM database backend, which ultimately yields remote code execution on the EPM server. A successful attack carries high impact to confidentiality, integrity, and availability of the server, effectively enabling full compromise of the management infrastructure. Organizations running EPM releases before the 2024 November Security Update, or before the 2022 SU6 November Security Update on the legacy branch, are affected. There are no known public proofs of concept or confirmed in-the-wild exploitation yet, but the elevated EPSS score (26.5%, 98th percentile) indicates a relatively high likelihood of exploitation within the next 30 days.
What to do: Apply the November 2024 Security Update on the EPM 2024 branch or the 2022 SU6 November Security Update on the EPM 2022 branch, treating this as a near-term priority given the elevated EPSS score. Until patched, restrict and audit administrative access to the EPM console and review admin accounts for anomalous activity. Check your installed EPM release/update level against the two named update packages to confirm whether you are in an affected range.
| Ivanti Endpoint Manager | Before the 2024 November Security Update (EPM 2024 branch); or before the 2022 SU6 November Security Update (legacy EPM 2022 branch) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated attacker with admin privileges to achieve remote code execution.
- Vendors
- ivanti
- Products
- endpoint manager
- Weakness
- CWE-89
- Vector
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.