Jan. 5, 2024, 11:45 a.m. | MalBot

Malware Analysis, News and Indicators - Latest topics malware.news

Ivanti has addressed a critical vulnerability in its Endpoint Manager (EPM) solution, identified as CVE-2023-39336, with a critical severity score of 9.6/10. This vulnerability, affecting EPM versions 2021 and 2022 prior to SU5, could enable Remote Code Execution (RCE) on affected servers.


The vulnerability involves an SQL injection that does not require authentication, allowing attackers to execute arbitrary SQL queries and potentially control machines running the EPM agent. The issue is especially severe when the core server uses SQL …

code code execution critical critical vulnerability cve enable endpoint epm ivanti manager patch rce remote code remote code execution score servers severity solution vulnerability

Information Security Engineers

@ D. E. Shaw Research | New York City

Technology Security Analyst

@ Halton Region | Oakville, Ontario, Canada

Senior Cyber Security Analyst

@ Valley Water | San Jose, CA

Principal Security Research Engineer (Prisma Cloud)

@ Palo Alto Networks | Bengaluru, India

National Security Solutions Fall 2024 Co-Op - Positioning, Navigation and Timing (PNT) Intern

@ KBR, Inc. | USA, Beavercreek Township, 4027 Colonel Glenn Highway, Suite 300, Ohio

Sr Principal Embedded Security Software Engineer

@ The Aerospace Corporation | HIA32: Cedar Rapids, IA 400 Collins Rd NE , Cedar Rapids, IA, 52498-0505 USA