ZeroHour
Help Net Securitypublished ()ingested @zeljkazorz

PoC exploit for Ivanti Endpoint Manager vulnerabilities released (CVE-2024-13159)

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-10811
Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated att

Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to leak sensitive information.

NVD description · AI analysis pending
7.54% PoC
  • ivanti endpoint manager
CVE-2024-13159
+2 in the same advisory: …13160 …13161
Unauthenticated Absolute Path Traversal Info Leak in Ivanti Endpoint Manager (EPM)

CVE-2024-13159 is an absolute path traversal vulnerability (CWE-36) in Ivanti Endpoint Manager (EPM) that allows a remote, unauthenticated attacker to leak sensitive information from the server. It is triggered when the EPM server processes attacker-supplied requests containing absolute file-system paths without properly constraining them, letting the attacker retrieve files outside the intended directory. A successful attack discloses arbitrary file contents, which could include configuration or credential material useful for further compromise; the available data describes information disclosure only, not code execution. Any organization running an Ivanti EPM management server, particularly one reachable by untrusted networks, is affected, though the source data does not specify affected version ranges. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2025-03-10, indicating confirmed in-the-wild exploitation, and EPSS assigns it a 100% probability of exploitation within 30 days; no public proof-of-concept is known.

Do: Apply the fixed updates identified in Ivanti's security advisory (specific patched versions are not included in the available data), and follow CISA KEV required action: apply vendor mitigations, comply with BOD 22-01 guidance for cloud services, or discontinue use if mitigations are unavailable. Until patched, restrict network access to the EPM management server to trusted networks and review HTTP/server logs for requests referencing absolute file paths that could indicate exploitation.

7.5100% KEV PoC
  • Ivanti Endpoint Manager (EPM)
largeon the order of tens of thousands of EPM management-server deployments (unknown share remotely exploitable)
Full article288 words · extracted from helpnetsecurity.com · click to collapse

A proof-of-concept (PoC) exploit for four critical Ivanti Endpoint Manager vulnerabilities has been released by Horizon3.ai researchers.

The vulnerabilities – CVE-2024-10811, CVE-2024-13161, CVE-2024-13160 and CVE-2024-13159 – may be exploited by remote, unauthenticated attackers to leverage Ivanti EPM machine account credentials for relay attacks and, ultimately, to compromise the Ivanti EPM server.

“Compromising the Endpoint Manager server itself would lead to the ability to compromise all of the EPM clients, making this avenue especially impactful,” Horizon3.ai researcher Zach Hanley explained last week, though he also noted that the impact of the exploitation would depend on the targeted environment.

The vulnerabilities

CVE-2024-10811, CVE-2024-13161, CVE-2024-13160 and CVE-2024-13159 are all path traversal flaws that could lead to leaking of sensitive information. Hanley disclosed them to Ivanti in October 2024.

Fixes for these and a dozen other less severe vulnerabilities were released by Ivanti in January 2025, and customers were urged to implement hot patches.

At the time, Ivanti confirmed that none of the flaws were under active exploitation, and that hasn’t changed.

But with the release of the PoC and the technical write-up, some attackers may have enough information and knowledge to fashion and leverage an exploit of their own.

Attackers have targeted vulnerable Ivanti Endpoint Manager appliances in the past, as well as other Ivanti enterprise solutions.

If you haven’t already upgraded to one of the fixed versions – EPM 2024 January-2025 Security Update or EPM 2022 SU6 January-2025 Security Update – you should do so now. In fact, even those that implemented an initial hotfix should update again, because that patch crippled a specific function of the software.

Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2025/02/24/poc-exploit-for-ivanti-endpoint-manager-vulnerabilities-released-cve-2024-13159/