TL;DR

A critical vulnerability in Ivanti Endpoint Manager exposes it to potential remote code execution via SQL injection after user authentication.

What happened

['Vulnerability discovered allowing RCE', 'SQL injection attack vector present']

Why it matters for ops

['Allows untrusted users with credentials to execute arbitrary commands on server', 'Exposes sensitive data and control of endpoint management']

Mitigation

  • Apply vendor-provided patches immediately
  • Limit admin privileges for non-admin users

Action items

  • Update to latest version of software
  • Review and restrict user permissions

Detection IOCs

  • Unexpected SQL error messages in logs
  • Unusual database access patterns

Source link

http://www.zerodayinitiative.com/advisories/ZDI-26-079/