{"id":287,"date":"2024-06-13T06:02:14","date_gmt":"2024-06-13T06:02:14","guid":{"rendered":"https:\/\/familiebuckens.nl\/?p=287"},"modified":"2024-06-14T06:02:59","modified_gmt":"2024-06-14T06:02:59","slug":"poc-exploit-emerges-for-critical-rce-bug-in-ivanti-endpoint-manager","status":"publish","type":"post","link":"https:\/\/familiebuckens.nl\/index.php\/2024\/06\/13\/poc-exploit-emerges-for-critical-rce-bug-in-ivanti-endpoint-manager\/","title":{"rendered":"PoC Exploit Emerges for Critical RCE Bug in Ivanti Endpoint Manager"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">A new month, a new high-risk Ivanti bug for attackers to exploit \u2014 this time, an SQL injection issue in its centralized endpoint manager. Researchers have developed a proof-of-concept (PoC) exploit for a critical vulnerability in Ivanti Endpoint Manager that was recently disclosed \u2014 potentially setting the stage for mass exploitation of the devices. CVE-2024-29824, an SQL injection bug, was first discovered by an independent researcher and sold to Trend Micro&#8217;s Zero Day Initiative (ZDI). ZDI\u00a0<a href=\"https:\/\/www.zerodayinitiative.com\/advisories\/ZDI-24-507\/\" target=\"_blank\" rel=\"noreferrer noopener\">informed Ivanti of the issue<\/a>\u00a0on April 3.<\/p>\n\n\n<a class=\"wp-block-read-more\" href=\"https:\/\/familiebuckens.nl\/index.php\/2024\/06\/13\/poc-exploit-emerges-for-critical-rce-bug-in-ivanti-endpoint-manager\/\" target=\"_self\"><a href=\"https:\/\/www.darkreading.com\/application-security\/poc-exploit-critical-rce-bug-ivanti-endpoint-manager\">PoC Exploit Emerges for Critical RCE Bug in Ivanti Endpoint Manager (darkreading.com)<\/a><span class=\"screen-reader-text\">: PoC Exploit Emerges for Critical RCE Bug in Ivanti Endpoint Manager<\/span><\/a>","protected":false},"excerpt":{"rendered":"<p>A new month, a new high-risk Ivanti bug for attackers to exploit \u2014 this time, an SQL injection issue in its centralized endpoint manager. Researchers have developed a proof-of-concept (PoC) exploit for a critical vulnerability in Ivanti Endpoint Manager that was recently disclosed \u2014 potentially setting the stage for mass&#8230;<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[20,17],"tags":[31],"class_list":["post-287","post","type-post","status-publish","format-standard","hentry","category-cybersecurity","category-vulnerability","tag-31"],"_links":{"self":[{"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/posts\/287","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/comments?post=287"}],"version-history":[{"count":1,"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/posts\/287\/revisions"}],"predecessor-version":[{"id":288,"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/posts\/287\/revisions\/288"}],"wp:attachment":[{"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/media?parent=287"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/categories?post=287"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/tags?post=287"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}