logo

Ivanti fixes maximum severity RCE bug in Endpoint Management software

ID: 755247c5-a196-58e6-8cb0-f8b50264e72e

STIX ID: report--755247c5-a196-58e6-8cb0-f8b50264e72e

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2024-09-10

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

Ivanti patched a critical unauthenticated RCE vulnerability (CVE-2024-29847) in Ivanti Endpoint Management stemming from unsafe deserialization in the agent portal; hot patches and EPM 2022 SU6 fixes were released. The company reports no known active exploitation of this specific flaw at disclosure but also addressed nearly two dozen other high/critical issues, and the advisory contextualizes this release within recent in-the-wild exploitation of other Ivanti zero-days affecting many customers.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.