Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Top Cooking Websites For Food Bloggers

    Katy Perry Goes To Space!

    Mr. Meowski’s Bakery To Re-Locate In St. Charles MO

    Facebook X (Twitter) Instagram
    Tech Empire Solutions
    • Home
    • Cloud
    • Cyber Security
    • Technology
    • Business Solution
    • Tech Gadgets
    Tech Empire Solutions
    Home » Ivanti releases patch for critical vulnerability in endpoint manager solution
    Cyber Security

    Ivanti releases patch for critical vulnerability in endpoint manager solution

    techempireBy techempire3 Comments2 Mins Read
    Facebook Twitter Pinterest Telegram LinkedIn Tumblr WhatsApp Email
    Share
    Facebook Twitter LinkedIn Pinterest Telegram Email

    ReportJanuary 5, 2024Editorial DepartmentVulnerabilities/Cyber ​​Security

    Vulnerabilities in Endpoint Manager solutions

    Ivanti has released a security update to address a critical flaw affecting its Endpoint Manager (EPM) solution that, if successfully exploited, could lead to Remote Code Execution (RCE) on vulnerable servers. .

    This vulnerability is numbered CVE-2023-39336 and scored 9.6 out of 10 on the CVSS scoring system. This flaw affects EPM 2021 and EPM 2022 prior to SU5.

    “If exploited, an attacker with access to the internal network could leverage unspecified SQL injection to execute arbitrary SQL queries and retrieve output without authentication,” Ivanti said in an advisory.

    Internet security

    “This could allow an attacker to take control of a computer running the EPM agent. This could lead to RCE on the core server when the core server is configured to use SQL Express.”

    A few weeks ago, the company addressed nearly two dozen security vulnerabilities in its Avalanche enterprise mobile device management (MDM) solution.

    Of these 21 issues, 13 are rated critical (CVSS score: 9.8) and characterized as unauthenticated buffer overflows. They have been patched in Avalanche 6.4.2.

    “An attacker sending a specially crafted packet to a mobile device server could cause memory corruption, leading to a denial of service (DoS) or code execution,” Ivanti said.

    Internet security

    While there is no evidence that the above vulnerabilities have been exploited in the wild, state-sponsored attackers have exploited zero-day vulnerabilities (CVE-2023-35078 and CVE-2023-35081) in Ivanti Endpoint Manager Mobile (EPMM) in the past to penetrate multiple Network of Norwegian government organizations.

    A month later, another critical vulnerability (CVE-2023-38035, CVSS score: 9.8) in the Ivanti Sentry product was actively exploited as a zero-day vulnerability.

    Did you find this article interesting?follow us Twitter  and LinkedIn to read more exclusive content from us.



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    techempire
    • Website

    Related Posts

    Ongoing campaign bombards businesses with spam emails and phone calls

    6 common mistakes organizations make when deploying advanced authentication

    New Chrome zero-day vulnerability CVE-2024-4761 is being actively exploited

    Microsoft patches 61 flaws, including two actively exploited zero-day vulnerabilities

    Dutch court sentences Tornado Cash co-founder to 5 years in prison for money laundering

    Migrate from VMware vSphere to Microsoft Azure

    Leave A Reply Cancel Reply

    Top Reviews
    Editors Picks

    Top Cooking Websites For Food Bloggers

    Katy Perry Goes To Space!

    Mr. Meowski’s Bakery To Re-Locate In St. Charles MO

    Pokémon Trading Card Website Making 100k!

    Legal Pages
    • About Us
    • Disclaimer
    • DMCA
    • Privacy Policy
    Our Picks

    Edufox

    Emerging Academic Education Platforms – Sponsored By Edufox

    GTA 6 Release Date

    Top Reviews

    Type above and press Enter to search. Press Esc to cancel.