Ivanti has fixed a critical remote code execution (RCE) vulnerability identified in its Endpoint Management (EPM) software. Successful exploitation could lead to a compromise of enrolled devices or the core server.

Ivanti EPM helps manage client devices running a wide range of platforms (e.g. Windows, macOS, Chrome OS, and IoT).
The new vulnerability patched by Ivanti is tracked as CVE-2023-39366 and affects all supported versions of Ivanti EPM. To protect yourself, use the 2022 Service Update 5.
See also: CISA warns of vulnerabilities in Chrome and Excel
Attackers with access to a target's internal network can exploit the vulnerability and carry out successful attacks quite easily, without requiring user interaction or extra privileges.
With the exploit and access to the internal network, the attacker can execute SQL queries and retrieve output without the need for authentication.
According to the company, this could then allow the attacker to take control of machines running the EPM agent.
“When the core server is configured to use SQL express, this can lead to RCE on the core server“.
The company says it has not discovered any evidence (at this time) that proves that the vulnerability in question has been abused against its customers.
See also: Ivanti patches critical vulnerabilities in Avalanche
Currently, Ivanti has not provided full details about the CVE-2023-39366 vulnerability until the update is applied by as many customers. The lack of details reduces the chances of cybercriminals creating an exploit.
Over the summer, two other vulnerabilities (CVE-2023-35078 and CVE-2023-35081) in Ivanti's Endpoint Manager Mobile (EPMM) were used in attacks to compromise the networks of several Norwegian government organizations.
“Mobile device management (MDM) systems are attractive targets for threat actors because they provide increased access to thousands of mobile devices , and APT actors have exploited a previous MobileIron vulnerability,” CISA warned.
A third zero-day vulnerability (CVE-2023-38035) in Sentry (formerly MobileIron Sentry) was also used in attacks in August.
Ivanti products are used by more than 40,000 companies worldwide to manage their IT assets and systems .

Protection against RCE vulnerabilities
To protect yourself from RCE vulnerabilities, it's essential to keep your software up to date. Developers typically issue security updates, as Ivanti has now done, to fix any vulnerabilities that have been discovered.
See also: Hackers exploit old MS Excel vulnerability to spread Agent Tesla malware
Additionally, using a vulnerability management system can help identify and address RCE vulnerabilities in a timely manner. These systems scan the network and applications to identify any vulnerabilities and provide solutions to resolve them.
Staff training is also critical. Users need to be aware of the techniques attackers use to exploit RCE vulnerabilities and how they can avoid executing malicious code.
Finally, the use of attack protection tools, such as systems (IPS) and exploit defense systems (EDR), can provide an additional layer of security by detecting and repelling attacks that attempt to exploit RCE vulnerabilities.
Source: www.bleepingcomputer.com
