Source: Cyber Security Advisories – MS-ISAC
Author: unknown
URL: https://www.cisecurity.org/advisory/multiple-vulnerabilities-in-ivanti-products-could-allow-for-remote-code-execution_2025-095
ONE SENTENCE SUMMARY:
Multiple vulnerabilities in Ivanti products may allow remote code execution, impacting systems depending on their user privileges.
MAIN POINTS:
- Multiple vulnerabilities found in Ivanti products could lead to remote code execution.
- Ivanti Endpoint Manager and Mobile versions prior to 2024 SU3 SR1 affected.
- Ivanti Neurons for MDM versions before R118 vulnerable to unauthorized access.
- Path traversal and SQL injection are key vulnerabilities discovered.
- Exploitations could allow attackers to install programs or alter data.
- No current reports of these vulnerabilities being actively exploited.
- Government and large businesses at high risk; small businesses at medium risk.
- Recommended actions include applying updates, vulnerability management, and patch management.
- Safeguards such as least privilege, network segmentation, and exploit protection are advised.
- Penetration testing and continuous review of system security recommended.
TAKEAWAYS:
- Apply Ivanti updates to address vulnerabilities immediately.
- Implement a robust vulnerability management and remediation strategy.
- Ensure systems and network infrastructure are up-to-date.
- Perform regular penetration testing to identify security gaps.
- Follow the principle of least privilege to minimize attack impact.