Vulnerability record · CVE-2024-34781 · published 13 November 2024
CVE-2024-34781: Ivanti Endpoint Manager SQL injection leads to remote code execution
Ivanti · Endpoint Manager
Ivanti Endpoint Manager before the 2024 November Security Update or 2022 SU6 November Security Update contains a SQL injection flaw (CWE-89). A remote attacker who already holds admin privileges can exploit it to run code on the server. Because the affected product is an endpoint management platform, successful exploitation can give an attacker control over managed endpoints.
Description
SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated attacker with admin privileges to achieve remote code execution.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityThe flaw enables remote code execution on a central management server, and the very high EPSS score signals likely exploitation, though it requires pre-existing admin privileges.
What it is
Ivanti Endpoint Manager before the 2024 November Security Update or 2022 SU6 November Security Update contains a SQL injection flaw (CWE-89). A remote attacker who already holds admin privileges can exploit it to run code on the server. Because the affected product is an endpoint management platform, successful exploitation can give an attacker control over managed endpoints.
Impact
An attacker with admin access gains remote code execution on the Endpoint Manager server, allowing full compromise of the host and, through it, the managed endpoint fleet.
Attack surface
Reachable over the network (AV:N) with no user interaction (UI:N), but it requires high privileges (PR:H) — the attacker must already be an authenticated admin. No public exploit details are given in the record.
Exploitation
CISA KEV does not list this CVE, but EPSS is very high at 0.68472 (99.3rd percentile), indicating a strong likelihood of exploitation activity. The only reference is the vendor advisory, which carries no exploit tag.
What to do
- Apply the Ivanti Endpoint Manager 2024 November Security Update or 2022 SU6 November Security Update immediately.
- Restrict and audit admin-level accounts on Endpoint Manager; enforce least privilege and remove unused admin accounts.
- Limit network exposure of the Endpoint Manager server to trusted management networks only.
- Monitor and alert on unexpected outbound connections or process creation on the Endpoint Manager host.
Detection
- Review Endpoint Manager and database logs for anomalous SQL queries or injection patterns from admin sessions.
- Alert on unexpected child processes spawned by the Endpoint Manager service or web server.
- Audit admin account activity for unusual login times, source IPs, or post-authentication actions.
- Monitor for new or modified files in web-accessible directories on the Endpoint Manager server.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://forums.ivanti.com/s/article/Security-Advisory-EPM-November-2024-for-EPM-2024-and-EPM-2022 | Vendor Advisory |
Track CVE-2024-34781 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2024-34781), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.