ZeroHour
Security Affairspublished ()ingested @securityaffairs

Security Affairs newsletter Round 489 by Pierluigi Paganini

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-29847
Unauthenticated Deserialization RCE in Ivanti Endpoint Manager Agent Portal

CVE-2024-29847 is a deserialization of untrusted data flaw (CWE-502) in the agent portal of Ivanti Endpoint Manager (EPM). A remote, unauthenticated attacker can send maliciously crafted serialized data to the agent portal, and processing of that input results in remote code execution on the EPM server. Because EPM core servers typically hold privileged roles in enterprise Windows environments, successful exploitation could provide a foothold for broader network compromise. Organizations running EPM before the 2022 SU6 release, or before the 2024 September update, are affected. The flaw was patched in September 2024 with no public PoC or confirmed in-the-wild exploitation yet, but its high EPSS (52.9%, 99th percentile) suggests exploitation is likely within 30 days, and it arrives amid separate active exploitation of other Ivanti products (the Cloud Service Appliance), raising attacker interest in Ivanti software generally.

Do: Upgrade to Ivanti EPM 2022 SU6 if on the 2022 release line, or apply the September 2024 update if on the 2024 line. Restrict network access to the EPM agent portal to trusted management segments and review EPM servers for signs of compromise given the current attention on Ivanti products. Review Ivanti's September 2024 EPM advisory for additional vulnerabilities fixed at the same time.

9.853%
  • Ivanti Endpoint Manager (EPM) - agent portal All versions before 2022 SU6
  • Ivanti Endpoint Manager (EPM) - agent portal All 2024-line versions before the September 2024 update
largetens of thousands of enterprise EPM deployments (internet-exposed footprint likely smaller)
CVE-2024-36401
Unauthenticated RCE in OSGeo GeoServer via GeoTools XPath Injection

OSGeo GeoServer ships the GeoTools library, which evaluates feature property names directly as XPath expressions without proper neutralization (CWE-95), so attacker-supplied input is executed as code rather than treated as data. A remote, unauthenticated attacker triggers the flaw by sending specially crafted requests to a GeoServer service, causing the injected expression to be evaluated in the server's context. Successful exploitation results in remote code execution on the host running GeoServer, giving the attacker control over the mapping server and any data or credentials it can reach. Any organization running GeoServer is affected, and the underlying GeoTools flaw also extends to dependent applications such as GeoNetwork, which shipped its own fix for an unauthenticated RCE chain affecting government geoportal backends. The flaw is being actively exploited: it was added to CISA KEV on 2024-07-15, and EPSS assigns a 99.8% probability of exploitation within 30 days.

Do: Upgrade GeoServer to the fixed releases identified in the OSGeo advisory (2.23.6, 2.24.4 or 2.25.2, or later); where upgrading is not immediately possible, restrict access to GeoServer's public endpoints per vendor mitigations or discontinue use of the product per the KEV required action. Organizations running GeoNetwork or other GeoTools-based applications should apply those vendors' fixes as well. Given active exploitation, hunt for signs of compromise such as unexpected child processes spawned by the GeoServer Java process, new files or services on the host, and unusual map/feature service request patterns.

9.8100% KEV PoC ×3
  • OSGeo GeoServer Multiple releases prior to the vendor-patched builds (fixed in the 2.23.x, 2.24.x and 2.25.x maintenance lines; exact fixed releases per the OSGeo advisory: 2.2
  • OSGeo GeoNetwork (bundles the vulnerable GeoTools library)
largeTens of thousands of internet-exposed instances (roughly 20,000-40,000 GeoServer endpoints visible in public internet scans), with substantially more internal…
Full article531 words · extracted from securityaffairs.com · click to collapse

Pierluigi Paganini September 15, 2024

A new round of the weekly SecurityAffairs newsletter arrived! Every week the best security articles from Security Affairs are free in your email box.

Enjoy a new round of the weekly SecurityAffairs newsletter, including the international press.

International Press – Newsletter

Cybercrime  

Russian And Kazakhstani Men Indicted For Running Dark Web Criminal Marketplaces, Forums, And Trainings      

Sextortion scam now use your “cheating” spouse’s name as a lure

Researchers trace massive data leak to US data broker: why should you care

Cyber-Attack on Payment Gateway Exposes 1.7 Million Credit Card Details  

Highline Public Schools closes schools following cyberattack

In Wake of Durov Arrest, Some Cybercriminals Ditch Telegram  

Six Persons To Be Charged For Offences In Relation To Illegal Cyber Activities  

UK arrests teen linked to Transport for London cyber attack

Fortinet suffers third-party data breach affecting Asia-Pacific customers  

Malware

Mythical Beasts and Where to Find Them: Mapping the Global Spyware Market and its Threats to National Security and Human Rights  

Malware’s Shared Secrets: Code Similarity Insights for Ransomware Gangs Activities Tracking      

Mallox ransomware: in-depth analysis and evolution  

A glimpse into the Quad7 operators’ next moves and associated botnets  

Ajina attacks Central Asia: Story of an Uzbek Android Pandemic      

Void captures over a million Android TV boxes

Hacking

Watch the Typo: Our PoC Exploit for Typosquatting in GitHub Actions

Threat Actors Exploit GeoServer Vulnerability CVE-2024-36401      

YubiKeys are vulnerable to cloning attacks thanks to newly discovered side channel 

Once and Forever: WhatsApp’s View Once Functionality is Broken  

PIXHELL Attack: Leaking Sensitive Information from Air-Gap Computers via `Singing Pixels’

Critical SonicWall SSLVPN bug exploited in ransomware attacks

Flipper Zero releases Firmware 1.0 after three years of development

DragonRank, a Chinese-speaking SEO manipulator service provider 

CVE-2024-29847 Deep Dive: Ivanti Endpoint Manager AgentPortal Deserialization of Untrusted Data Remote Code Execution Vulnerability

Living off the land, GPO style      

Intelligence and Information Warfare 

DeFied Expectations — Examining Web3 Heists         

Australian links revealed in global defence company scandal involving China, Russia and Iran  

TIDRONE Targets Military and Satellite Industries in Taiwan  

MI6 and CIA warn of ‘reckless campaign of sabotage across Europe’ being waged by Russia

Earth Preta Evolves its Attacks with New Malware and Strategies

Chinese APT Abuses VSCode to Target Government in Asia  

Poland neutralises sabotage group linked to Belarus and Russia  

Fake recruiter coding tests target devs with malicious Python packages

Cybersecurity

25 Ways to Make the SOC More Efficient and Avoid Team Burnout  

An Open door

The September 2024 Security Update Review  

The rise of fake influencers  

Bug Left Some Windows PCs Dangerously Unpatched 

YARA Rule Crafting: A Deep Dive into Signature-Based Threat Hunting Strategies  

WordPress.org to require 2FA for plugin developers by October

Data Protection Commission launches inquiry into Google AI model

Building a Cybersecurity and Privacy Learning Program

UK Data Centers Gain Critical Infrastructure Status, Raising Green Belt Controversy

Record $65 Million Settlement Reached Between Saltz Mongeluzzi Bendesky and LVHN on Behalf of Cancer Patients Whose Nude Photos Were Hacked

Facebook scrapes photos of kids from Australian user profiles to train its AI      

Global Cybersecurity Index  

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, newsletter)



you might also like

leave a comment

Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/168403/breaking-news/security-affairs-newsletter-round-489-by-pierluigi-paganini-international-edition.html