Critical Ivanti Endpoint Manager flaw exploited (CVE-2024-29824)
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2024-29824 | Unauthenticated SQL Injection to RCE in Ivanti Endpoint Manager (EPM) Core Server CVE-2024-29824 is a SQL injection flaw (CWE-89) in the Core server component of Ivanti Endpoint Manager (EPM), Ivanti's on-premises endpoint management platform. An unauthenticated attacker who can reach the EPM Core server over the network can send crafted input that is passed unsafely to the underlying database, and the flaw ultimately permits execution of arbitrary code on the server. Successful exploitation gives an attacker control of the EPM Core server, which manages an organization's endpoint fleet, typically yielding broad enterprise-level privileges useful for lateral movement; ransomware use has not been confirmed. Any organization running an affected EPM Core server is exposed, though because the attack requires access to the same network, the primary risk is from attackers already inside the network or on compromised managed endpoints rather than direct internet-facing attacks. The vulnerability was added to CISA's KEV catalog on 2024-10-02, confirming exploitation in the wild, and EPSS assigns it a 100% probability of exploitation within 30 days (100th percentile); a CVSS score is not yet available and no public proof-of-concept is known. Do: Apply Ivanti's patched service update for your EPM release immediately per the vendor's instructions, prioritizing any Core server reachable from user or untrusted network segments; the KEV listing gives federal agencies a mandatory remediation deadline. As interim mitigation, restrict network access to the EPM Core server's services to management networks and administrators, and hunt for anomalous database activity or unexpected process launches on Core servers. | 8.8 | 100% | KEV |
| largetens of thousands of enterprise deployments (order of ~10,000-100,000 EPM Core servers; exact install base unpublished) |
Full article360 words · extracted from helpnetsecurity.com · click to collapse
CVE-2024-29824, an unauthenticated SQL Injection vulnerability in Ivanti Endpoint Manager (EPM) appliances, is being exploited by attackers, the Cybersecurity and Infrastructure Security Agency has confirmed by adding the bug to its Known Exploited Vulnerabilities catalog.

Ivanti did the same by updating the relevant security advisory to say that they are aware of a limited number of customers who have been exploited. Further details about the attacks are unavailable at this time.
About CVE-2024-29824
CVE-2024-29824, reported by an anonymous researcher via the Zero Day Initiative program, is one of the ten SQL injection vulnerabilities Ivanti has released a fix for in May 2024.
They all affect the core server of Ivanti EPM 2022 SU5 and prior versions, can lead to code execution in the context of the service account, and all have been fixed through a security hot patch.
ZDI’s advisory described CVE-2024-29824 as a flaw that exists within the implementation of the RecordGoodApp method and is due to the lack of proper validation of a user-supplied string before using it to construct SQL queries.
That was enough to point Horizon3.ai researchers in the right direction, and they published technical details about the vulnerability and a PoC exploit in June 2024.
What to do?
The addition of CVE-2024-29824 to the KEV catalog means that all US federal civilian executive branch agencies must remediate it by October 23, 2024.
The patch provided by Ivanti is implemented by replacing five DLL files from the core server with five others (with the same name) contained in the patch. The process has to be concluded by either restarting the core server or closing the EPM console and running IISRESET (a command for restarting IIS services), so that the new DLL files are loaded.
At an (unclear) date that came after the intial release of its advisory, Ivanti has made changes to the patch and urged users to update some of the files or implement the new patch if they haven’t previously done so. So check the advisory and do what needs to be done.

Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2024/10/03/cve-2024-29824/