Ivanti Security Updates – 06 January 2024

Ivanti has released security updates to address a critical flaw that affects Ivanti Endpoint Manager (EPM) version 2022 SU4 and all prior versions.

The addressed vulnerability could allow the attacker to execute arbitrary SQL queries, retrieve output without the need for authentication, and control machines running the EPM agent. This applies to all instances of MSSQL.

Additionally, when the core server is configured to use Microsoft SQL Express, this might lead to RCE on the core server.

Ivanti Endpoint Manager SQL Injection Vulnerability (CVE-2023-39336):

  • CVSS: 9.6
  • Attack Vector: Adjacent Network
  • Attack Complexity: Low
  • Privileges Required: None
  • User Interaction: None
  • Consequences: Gain Access
Vulnerabilities

CVE-2023-39336

Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

Ivanti Security Advisory

References