CVE-2024-50330
largeUnauthenticated SQL Injection RCE in Ivanti Endpoint Manager
CVE-2024-50330 is a SQL injection flaw (CWE-89) in Ivanti Endpoint Manager (EPM) that allows a remote, unauthenticated attacker to achieve remote code execution, and it carries a critical CVSS 9.8 score. It is triggered when crafted input reaches a vulnerable EPM database-backed component over the network, requiring no credentials, privileges, or user interaction. A successful attacker gains code execution on the EPM server, which typically anchors the management of an organization's Windows endpoint estate and can serve as a foothold for lateral movement into the enterprise network. Any organization running EPM before the 2024 November Security Update, or on the 2022 SU branch before the 2022 SU6 November Security Update, is affected. No in-the-wild exploitation, public proof-of-concept, or KEV listing is known yet, but EPSS assigns a roughly 40% probability of exploitation within 30 days, so patching urgency is high.
What to do: Upgrade EPM to the 2024 November Security Update, or apply the 2022 SU6 November Security Update if running the 2022 SU branch. Until patched, restrict network access to the EPM core server and its web/database-facing components and review SQL and application logs for anomalous queries. Given the high EPSS score, monitor vendor advisories and threat intel for signs of imminent exploit activity.
| Ivanti Endpoint Manager | EPM 2024 before the 2024 November Security Update; EPM 2022 SU branch before the 2022 SU6 November Security Update |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote unauthenticated attacker to achieve remote code execution.
- Vendors
- ivanti
- Products
- endpoint manager
- Weakness
- CWE-89
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.