Ivanti has released security updates to fix 27 vulnerabilities in its mobile device(MDM) solution, Avalanche. Two of these vulnerabilities have been rated “critical” and could be exploited for remote command execution.

Avalanche is used by business to remotely manage, deploy software, and schedule updates across thousands of mobile devices, from a single central location.
According to Ivanti, the two critical vulnerabilities are tracked as CVE-2024-24996 and CVE-2024-29204 and were found in the WLInfoRailService and WLAvalancheService components of Avalanche. They allow unauthenticated remote attackers to execute commands on vulnerable systems. The attacks are not complex and do not require user interaction.
See also: Ivanti patches vulnerabilities in Connect Secure gateways
The remaining 25 vulnerabilities fixed by the company are of medium and high severity and could also be used by remote attackers for denial-of-service attacks, execution of SYSTEM commands, reading sensitive information from memory, and remote code execution.
The company said it currently has no evidence that any customers have been affected by these vulnerabilities.
“To address security vulnerabilities, it is highly recommended to download the Avalanche installer and update to the latest Avalanche 6.4.3.” Customers can find more information about upgrade steps in this article.
“ Mobile device management (MDM) systems are attractive targets for threat actors because they provide increased access to thousands of mobile devices ,” CISA said last August. For this reason, it is essential to apply the updates released by Ivanti for Avalanche to fix the vulnerabilities.
See also: Ivanti patches a critical Standalone Sentry vulnerability
Best practices for applying updates
The best practices for implementing software updates to improve cybersecurityare essentially the following: First, it is important to have a well-organized update management process. This includes monitoring available updates, assessing their importance, and prioritizing their installation.

Second, it's important to apply updates as soon as possible after they're released. Updates contain fixes for known security, so delaying their installation can expose your system to risks.
See also: Five Eyes: Warns of exploitation of Ivanti vulnerabilities
Third, you need to ensure that updates are installed correctly and completely. This includes performing a full compatibility check with the existing system, creating backups before installation, and monitoring the process for any errors or issues.
Finally, it's important to keep software up to date. Cybersecurity attacks and threats are constantly evolving, so keeping your software up to date is crucial to keeping system .
Source: www.bleepingcomputer.com
