Active Exploitation of Critical Flaws in Ivanti EPM

Red | Vulnerability Report
Download PDF

Ivanti has patched two critical vulnerabilities, CVE-2024-29824 and CVE-2024-29847, in its Endpoint Manager (EPM). These flaws allow unauthenticated attackers to execute arbitrary code, leading to full system compromise. CVE-2024-29847 involves insecure deserialization, while CVE-2024-29824 is an SQL injection vulnerability. Both are actively exploited, and proof-of-concept (PoC) exploit code is publicly available, making immediate patching essential.

What’s new on HivePro

Get through updates and upcoming events, and more directly in your inbox