CyberzSOC

Publication detail
← Back to advisories & guidance

2024-041: Multiple Vulnerabilities in Ivanti Avalanche MDM ↗ source

April 17, 2024 CERT-EU Advisory

Summary

The two critical security flaws, tracked as CVE-2024-24996 and CVE-2024-29204, with CVSS score of 9.8, were found in Avalanche’s WLInfoRailService and WLAvalancheService components [1]. They are both caused by heap-based buffer overflow weaknesses, which can let unauthenticated remote attackers execute arbitrary commands on vulnerable systems in low-complexity attacks that do not require user interaction [1]. The 25 other vulnerabilities are ranging from medium to high severity, and can lead to denial of service conditions, unauthorised command execution as SYSTEM , and sensitive information Avalanche MDM versions before version 6.4.3. CERT-EU recommends updating to the fixed version as soon as possible [2].

News Coverage

No coverage found in monitored research blogs or news feeds.

CVEs Referenced in This Publication

CVECVSSAffected
CVE-2024-24996 9.8 Critical Ivanti Avalanche A Heap overflow vulnerability in WLInfoRailService component of Ivanti Avalanche before 6.4.3 allows an unauthenticated remote attacker to execute ar…
CVE-2024-29204 9.8 Critical Ivanti Avalanche A Heap Overflow vulnerability in WLAvalancheService component of Ivanti Avalanche before 6.4.3 allows a remote unauthenticated attacker to execute ar…

Extracted from the publication text. Each CVE links to its tracked detail page.

Vendors Named in This Publication

Each vendor links to its Known Exploited Vulnerabilities catalog page. Only vendors that appear in the KEV catalog are listed, either because the publication cites one of their KEV entries or because it names them directly.