Ivanti patches serious endpoint management software security bugs, so update now

A person's fingers type at a keyboard, with a digital security screen with a lock on it overlaid.
(Image credit: Shutterstock / Thapana_Studio)

Ivanti has released a patch for a critical security vulnerability, advising users to apply it immediately to secure their infrastructure.

In an advisory, Ivanti said it had uncovered a deserialization of untrusted data weakness in its Endpoint Management (EPM) agent portal. The vulnerability is tracked as CVE-2024-29847 and carries a maximum severity score.

Ivanti said the bug allows unauthenticated threat actors to remotely execute malicious code on the core server: "Successful exploitation could lead to unauthorized access to the EPM core server," the company explained. The good news is that there is no evidence of the bug being exploited in the wild (yet) - and users should look for Ivanti EPM 2024 hot patches, as well Ivanti EPM 2022 Service Update 6 (SU6), since these address the problem.

Fixing numerous bugs

Ivanti Endpoint Management is a software solution that helps organizations manage, secure, and optimize devices across their networks. It allows IT teams to automate tasks such as software deployment, patch management, and device configuration while ensuring endpoint security and compliance.

The platform supports various operating systems, including Windows, macOS, and mobile devices, and offers centralized control for streamlined management. By using Ivanti, businesses can reduce IT complexity, enhance device performance, and minimize security risks across their endpoint infrastructure.

Together with this flaw, Ivanti has addressed numerous other bugs, including a number of critical severity vulnerabilities in Ivanti EPM, Workspace Control (IWC), and Cloud Service Appliance (CSA). The company says none of these flaws were abused in the wild.

However, now with the news of the vulnerabilities out there, it’s only a matter of time before someone steps up with a Proof-of-Concept and starts scanning for flawed endpoints. Ivanti’s products are used by more than 40,000 organizations worldwide, and as such, is a major target.

Via BleepingComputer

More from TechRadar Pro

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
Representational image depecting cybersecurity protection
Ivanti reveals major security update, so make sure you're protected
vpn
Ivanti warns another critical security flaw is being attacked
A person at a laptop with a cybersecure lock symbol floating above it.
Hackers are still using old Ivanti bugs to break into networks
A person's fingers type at a keyboard, with a digital security screen with a lock on it overlaid.
Veeam backup software has a serious security flaw - here's how to stay safe
The best free firewall
Sophos hotfixes remote code execution vulnerabilities in Firewall
Best free Linux firewalls
SonicWall tells admins to patch worrying SSLVPN flaw immediately
Latest in VPN Privacy & Security
Teenager playing on a gaming PC with two monitors
Is using a VPN while gaming cheating? 5 myths you shouldn't believe about gaming with a VPN
Neon blue email symbols on a black background
Why am I suddenly getting so many spam emails?
A computer file surrounded by red laser beams
Cover your tracks: the risk of sending unencrypted files
Using an Amazon Fire Stick on a Smart TV
How to use a VPN with Fire Stick
Close up of PS5 DualSense controller leaning on a PS5
5 reasons your PS5 needs a VPN
Tor
What is Onion over VPN?
Latest in News
UK Prime Minister Sir Kier Starmer
The UK releases timeline for migration to post-quantum cryptography
The Samsung Galaxy S25 Edge on display the January 22, 2025 Galaxy Unpacked event.
A fresh Samsung Galaxy S25 Edge benchmark leak has eased my worries about its performance
Gmail at 20
Your Gmail search results are about to get a huge change - and I'm not sure you're going to be happy with it
Google Pixel 9 in green Wintergreen color showing AI features on screen
Older Pixels just got a big performance boost, while the Pixel 9a is lacking a key feature
Google Pixel Watch 3
Google Pixel Watch 3's Loss of Pulse Detection could save your life – here's how the company created it
Wonka poster
Netflix cooks up sweet new reality TV series based on Charlie and the Chocolate Factory, and it's a dream come true for me