Source: www.csoonline.com – Author:
Three of the four critical path traversal flaws fixed in January in Ivanti Endpoint Manager are being exploited in cyberattacks after proof-of-concept exploit code was released last month.
The US Cybersecurity and Infrastructure Security agency has added three vulnerabilities in Ivanti Endpoint Manager (EPM) to its known exploited vulnerabilities (KEV) catalog signaling they’ve seen in-the-wild exploitation. The flaws received patches in January after being reported privately to Ivanti by the researcher who found them.
The three vulnerabilities, tracked as CVE-2024-13159, CVE-2024-13160, and CVE-2024-13161 are described by Ivanti as absolute path traversals and were part of a larger patch that addressed four critical and 12 high-severity flaws. The company noted at the time it had no evidence of these flaws being exploited in the wild.
The three vulnerabilities, plus a fourth one, were discovered and reported to Ivanti by researcher Zach Hanley with penetration testing firm Horizon3.ai. Hanley wrote up the research in a blog post in February that also included proof-of-concept exploit code.
Credential coercion
Hanley described the flaws as credential coercion issues because they could allow unauthenticated attackers to coerce the Ivanti EPM machine account credential to be used in NTLM relay attacks, which could in turn result in server compromise.
Ivanti EPM is an asset monitoring and management solution for enterprises that can manage a variety of desktop and mobile devices. The server component is an application written in .NET that exposes various API endpoints.
Hanley found that the input to several unauthenticated API endpoints was not properly sanitized and could be used to pass UNC absolute paths to several methods: GetHashForFile, GetHashForSingleFile, GetHashForWildcard and GetHashForWildcardRecursive — all of which had to do with obtaining hashes for files in specified directories.
SUBSCRIBE TO OUR NEWSLETTER
From our editors straight to your inbox
Get started by entering your email address below.
Original Post url: https://www.csoonline.com/article/3843301/ivanti-epm-vulnerabilities-actively-exploited-in-the-wild-cisa-warns.html
Category & Tags: Patch Management Software, Security, Vulnerabilities – Patch Management Software, Security, Vulnerabilities
Views: 3