logo

Ivanti Patches Critical Remote Code Execution Flaws in Endpoint Manager

ID: 26a82063-020a-575d-9955-74329e82de33

STIX ID: report--26a82063-020a-575d-9955-74329e82de33

Feed Name: The Hacker News

Threat Score
70/100

Date Published: 2024-05-23

Date Updated: 2026-05-05

Author: [email protected] (The Hacker News)

...
...

Multiple critical vulnerabilities were disclosed and patched across several products: Ivanti Endpoint Manager (multiple SQL injection flaws enabling potential unauthenticated or authenticated remote code execution), Avalanche (file upload RCE), Neurons for ITSM (SQL injection and unrestricted file upload), Connect Secure (CRLF injection), Secure Access clients (local privilege escalation), and a path-traversal RCE in the open-source Netflix Genie prior to 4.3.18. Vendors released fixes and noted limited/no evidence of exploitation for the Ivanti issues, while maintainers warned Genie OSS instances that store attachments on the local filesystem are at risk of arbitrary file write and potential RCE.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.