Threat Advisory

Critical Vulnerabilities in Ivanti EPM Exposed with PoC Code

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

score of 9.8. The flaws exist in functions that process user input when reading files from specific paths and calculating hashes, allowing an unauthenticated attacker to exploit the system. By exploiting these vulnerabilities, an attacker can manipulate the EPM server into connecting to remote UNC paths, potentially leading to relay attacks. This could result in leaking sensitive information or compromising server credentials. The vulnerabilities enable attackers to relay credentials to LDAP, add machine accounts, and escalate privileges to impersonate domain administrators for CIFS services. If the EPM server is compromised, all connected clients are also at risk, making the potential impact particularly severe. These vulnerabilities were first reported in October 2024, and the full technical details have now been revealed, highlighting the critical nature of the flaws and the risk they pose to affected systems.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

score of 9.8. The flaws exist in functions that process user input when reading files from specific paths and calculating hashes, allowing an unauthenticated attacker to exploit the system. By exploiting these vulnerabilities, an attacker can manipulate the EPM server into connecting to remote UNC paths, potentially leading to relay attacks. This could result in leaking sensitive information or compromising server credentials. The vulnerabilities enable attackers to relay credentials to LDAP, add machine accounts, and escalate privileges to impersonate domain administrators for CIFS services. If the EPM server is compromised, all connected clients are also at risk, making the potential impact particularly severe. These vulnerabilities were first reported in October 2024, and the full technical details have now been revealed, highlighting the critical nature of the flaws and the risk they pose to affected systems.[emaillocker id="1283"]

  • CVE-2024-10811: This vulnerability involves absolute path traversal in Ivanti Endpoint Manager, where user input is not properly validated. An attacker can exploit this to read arbitrary files from the server, potentially revealing sensitive information and compromising security. This can lead to further exploitation via remote code execution or credential theft.
  • CVE-2024-13161: This vulnerability allows unauthenticated attackers to manipulate Ivanti EPM into connecting to a remote UNC path. By doing so, an attacker can cause the system to relay sensitive credentials to an external server. This flaw could be leveraged to gain unauthorized access to a system, compromising the integrity of the server and its clients.
  • CVE-2024-13160: This flaw stems from improper handling of user input when reading files and calculating hashes in Ivanti EPM. The vulnerability can be exploited to make the EPM server connect to a malicious server, exposing machine account credentials. This can further lead to privilege escalation attacks, where attackers can impersonate higher-level users or administrators.

CVE-2024-13159: Similar to other path traversal issues, this vulnerability occurs in Ivanti EPM and allows attackers to manipulate the file reading function. By coercing the server to access a remote UNC path, attackers can relay credentials to an LDAP server, giving them the ability to create a new machine account and escalate privileges for malicious purposes.

RECOMMENDATION:

We strongly recommend you update Ivanti Endpoint Manager (EPM) to below version Download from here: https://forums.ivanti.com/s/article/Security-Advisory-EPM-January-2025-for-EPM-2024-and-EPM-2022-SU6?language=en_US

REFERENCES:

The following reports contain further technical details:
https://www.securityweek.com/poc-exploit-published-for-critical-ivanti-epm-vulnerabilities/

 

[/emaillocker]
crossmenu