Ivanti patches serious endpoint management software security bugs, so update now
Ivanti has released a patch for a critical security vulnerability, advising users to apply it immediately to secure their infrastructure.
In an advisory, Ivanti said it had uncovered a deserialization of untrusted data weakness in its Endpoint Management (EPM) agent portal. The vulnerability is tracked as CVE-2024-29847 and carries a maximum severity score.
Ivanti said the bug allows unauthenticated threat actors to remotely execute malicious code on the core server: “Successful exploitation could lead to unauthorized access to the EPM core server,” the company explained. The good news is that there is no evidence of the bug being exploited in the wild (yet) – and users should look for Ivanti EPM 2024 hot patches, as well Ivanti EPM 2022 Service Update 6 (SU6), since these address the problem.
Fixing numerous bugs
Ivanti Endpoint Management is a software solution that helps organizations manage, secure, and optimize devices across their networks. It allows IT teams to automate tasks such as software deployment, patch management, and device configuration while ensuring endpoint security and compliance.
The platform supports various operating systems, including Windows, macOS, and mobile devices, and offers centralized control for streamlined management. By using Ivanti, businesses can reduce IT complexity, enhance device performance, and minimize security risks across their endpoint infrastructure.
Together with this flaw, Ivanti has addressed numerous other bugs, including a number of critical severity vulnerabilities in Ivanti EPM, Workspace Control (IWC), and Cloud Service Appliance (CSA). The company says none of these flaws were abused in the wild.
However, now with the news of the vulnerabilities out there, it’s only a matter of time before someone steps up with a Proof-of-Concept and starts scanning for flawed endpoints. Ivanti’s products are used by more than 40,000 organizations worldwide, and as such, is a major target.
Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!
Via BleepingComputer
More from TechRadar Pro
Ivanti has released a patch for a critical security vulnerability, advising users to apply it immediately to secure their infrastructure. In an advisory, Ivanti said it had uncovered a deserialization of untrusted data weakness in its Endpoint Management (EPM) agent portal. The vulnerability is tracked as CVE-2024-29847 and carries a…
Recent Posts
- Nintendo confirms it will sell a new Switch 2 with replaceable battery in the EU
- Apple begins requiring age verification for App Store use in Texas
- The co-creator of Scavengers Reign is working on a new show for Netflix
- Apple is bringing age verification to Texas this week
- How to watch NBA Finals 2026: Free streams, schedule, TV channels for New York Knicks vs San Antonio Spurs
Archives
- June 2026
- May 2026
- April 2026
- March 2026
- February 2026
- January 2026
- December 2025
- November 2025
- October 2025
- September 2025
- August 2025
- July 2025
- June 2025
- May 2025
- April 2025
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023