TL;DR

A critical vulnerability exists in Ivanti Endpoint Manager that allows remote attackers to bypass authentication, posing a significant security risk.

What happened

['Remote attacker can exploit the AuthHelper service', 'Bypasses authentication without credentials', 'Exploitation does not require admin rights']

Why it matters for ops

['Allows unauthorized access to systems', 'Increases likelihood of data breaches', 'Can lead to full system compromise']

Mitigation

  • Apply available security patches immediately
  • Monitor and restrict access to AuthHelper service
  • Implement multi-factor authentication

Action items

  • Update to latest version of Ivanti Endpoint Manager
  • Review system permissions and access controls
  • Enable logging and alerts for suspicious activities

Detection IOCs

  • Unusual network traffic patterns
  • Authentication bypass attempts in logs

Source link

http://www.zerodayinitiative.com/advisories/ZDI-26-080/