April 17, 2024, 12:48 p.m. | Jimi Sebree

Tenable Research Advisories www.tenable.com

Ivanti Avalanche WLAvalancheService.exe Unauthenticated Heap-based Buffer Overflow

A heap-based buffer overflow vulnerability exists in Ivanti Avalanche prior to 6.4.3.

A message sent to Avalanche's WLAvalancheService.exe on TCP port 1777 has the following structure:

// be = big-endian
strut msg
{
preamble pre;
hp hdrpay;
};
struct preamble
{
be32 MsgSize; // size of hp + 16
be32 HdrSize; // size of hp.hdr
be32 PayloadSize; // size of hp.payload
be32 unk:24;
be32 em:8; // encryption method
};
// header + payload …

avalanche big buffer buffer overflow buffer overflow vulnerability ivanti ivanti avalanche message msg overflow port size structure tcp unauthenticated vulnerability

Information Security Engineers

@ D. E. Shaw Research | New York City

Technology Security Analyst

@ Halton Region | Oakville, Ontario, Canada

Senior Cyber Security Analyst

@ Valley Water | San Jose, CA

COMM Penetration Tester (PenTest-2), Chantilly, VA OS&CI Job #368

@ Allen Integrated Solutions | Chantilly, Virginia, United States

Consultant Sécurité SI H/F Gouvernance - Risques - Conformité

@ Hifield | Sèvres, France

Infrastructure Consultant

@ Telefonica Tech | Belfast, United Kingdom