EXECUTIVE SUMMARY:
score of 9.8. The flaws exist in functions that process user input when reading files from specific paths and calculating hashes, allowing an unauthenticated attacker to exploit the system. By exploiting these vulnerabilities, an attacker can manipulate the EPM server into connecting to remote UNC paths, potentially leading to relay attacks. This could result in leaking sensitive information or compromising server credentials. The vulnerabilities enable attackers to relay credentials to LDAP, add machine accounts, and escalate privileges to impersonate domain administrators for CIFS services. If the EPM server is compromised, all connected clients are also at risk, making the potential impact particularly severe. These vulnerabilities were first reported in October 2024, and the full technical details have now been revealed, highlighting the critical nature of the flaws and the risk they pose to affected systems.[/subscribe_to_unlock_form]
EXECUTIVE SUMMARY:
score of 9.8. The flaws exist in functions that process user input when reading files from specific paths and calculating hashes, allowing an unauthenticated attacker to exploit the system. By exploiting these vulnerabilities, an attacker can manipulate the EPM server into connecting to remote UNC paths, potentially leading to relay attacks. This could result in leaking sensitive information or compromising server credentials. The vulnerabilities enable attackers to relay credentials to LDAP, add machine accounts, and escalate privileges to impersonate domain administrators for CIFS services. If the EPM server is compromised, all connected clients are also at risk, making the potential impact particularly severe. These vulnerabilities were first reported in October 2024, and the full technical details have now been revealed, highlighting the critical nature of the flaws and the risk they pose to affected systems.[emaillocker id="1283"]
CVE-2024-13159: Similar to other path traversal issues, this vulnerability occurs in Ivanti EPM and allows attackers to manipulate the file reading function. By coercing the server to access a remote UNC path, attackers can relay credentials to an LDAP server, giving them the ability to create a new machine account and escalate privileges for malicious purposes.
RECOMMENDATION:
We strongly recommend you update Ivanti Endpoint Manager (EPM) to below version Download from here: https://forums.ivanti.com/s/article/Security-Advisory-EPM-January-2025-for-EPM-2024-and-EPM-2022-SU6?language=en_US
REFERENCES:
The following reports contain further technical details:
https://www.securityweek.com/poc-exploit-published-for-critical-ivanti-epm-vulnerabilities/
[/emaillocker]