Ivanti Warns of Another Endpoint Manager Mobile Vulnerability Under Active Attack

Teilen:

Ivanti has disclosed yet another security flaw impacting Endpoint Manager Mobile (EPMM), formerly known as MobileIron Core, that it said has been weaponized as part of an exploit chain by malicious actors in the wild.

The new vulnerability, tracked as CVE-2023-35081 (CVSS score: 7.8), impacts supported versions 11.10, 11.9, and 11.8, as well as those that are currently end-of-life (EoL).

CVE-2023-35081 enables an authenticated administrator to perform arbitrary file writes to the EPMM server, the company said in an advisory. This vulnerability can be used in conjunction with CVE-2023-35078, bypassing administrator authentication and ACLs restrictions (if applicable).

A successful exploit could allow a threat actor to write arbitrary files on the appliance, thereby enabling the malicious party to execute OS commands on the appliance as the tomcat user.

As of now we are only aware of the same limited number of customers impacted by CVE-2023-35078 as being impacted by CVE-2023-35081, the company added.

Cybersecurity firm Mnemonic, which discovered and reported the flaw, said it observed CVE-2023-35081 being used together with CVE-2023-35078 to write JSP and Java .class files to disk.

These files were loaded into a running Apache Tomcat instance and enabled an external actor to run malicious Java bytecode on the affected servers, the company said.

It’s worth noting that CVE-2023-35078 is a critical remote unauthenticated API access vulnerability that permits remote attackers to obtain sensitive information, add an EPMM administrative account, and change the configuration because of an authentication bypass.

The security flaws have been exploited by unknown actors targeting Norwegian government entities, prompting the U.S. Cybersecurity and Infrastructure Security Agency (CISA) to release an alert urging users and organizations to apply the latest fixes.

The development also comes as the Google Project Zero team said 41 in-the-wild 0-days were detected and disclosed in 2022, down from 69 in 2021, noting that 17 of those are variants of previously public vulnerabilities.

Similar to the overall numbers, there was a 42% drop in the number of detected in-the-wild 0-days targeting browsers from 2021 to 2022, dropping from 26 to 15, Google TAG researcher Maddie Stone said.

We assess this reflects browsers’ efforts to make exploitation more difficult overall as well as a shift in attacker behavior away from browsers towards zero-click exploits that target other components on the device.

 

(c) Thin

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
9:44 am, Juni 1, 2025
Wetter-Symbol 16°C
L: 15° | H: 17°
wenige Wolken
Luftfeuchtigkeit: 64 %
Druck: 1014 mb
Wind: 14 mph W
Windböe: 0 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 20%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 4:49 am
Sonnenuntergang: 9:07 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Today 10:00 pm
Wetter-Symbol
15° | 17°°C 0 mm 0% 14 mph 70 % 1014 mb 0 mm/h
Tomorrow 10:00 pm
Wetter-Symbol
11° | 21°°C 0 mm 0% 10 mph 82 % 1019 mb 0 mm/h
Di. Juni 03 10:00 pm
Wetter-Symbol
11° | 17°°C 1 mm 100% 16 mph 92 % 1013 mb 0 mm/h
Mi. Juni 04 10:00 pm
Wetter-Symbol
9° | 19°°C 0 mm 0% 13 mph 83 % 1010 mb 0 mm/h
Do. Juni 05 10:00 pm
Wetter-Symbol
11° | 15°°C 1 mm 100% 13 mph 97 % 1009 mb 0 mm/h
Today 10:00 am
Wetter-Symbol
16° | 16°°C 0 mm 0% 10 mph 63 % 1014 mb 0 mm/h
Today 1:00 pm
Wetter-Symbol
16° | 17°°C 0 mm 0% 12 mph 57 % 1014 mb 0 mm/h
Today 4:00 pm
Wetter-Symbol
16° | 16°°C 0 mm 0% 14 mph 45 % 1013 mb 0 mm/h
Today 7:00 pm
Wetter-Symbol
15° | 15°°C 0 mm 0% 12 mph 51 % 1013 mb 0 mm/h
Today 10:00 pm
Wetter-Symbol
16° | 16°°C 0 mm 0% 9 mph 70 % 1014 mb 0 mm/h
Tomorrow 1:00 am
Wetter-Symbol
13° | 13°°C 0 mm 0% 7 mph 82 % 1016 mb 0 mm/h
Tomorrow 4:00 am
Wetter-Symbol
11° | 11°°C 0 mm 0% 6 mph 78 % 1017 mb 0 mm/h
Tomorrow 7:00 am
Wetter-Symbol
12° | 12°°C 0 mm 0% 9 mph 72 % 1018 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€91,948.58
0.62%
Ethereum(ETH)
€2,208.62
-0.65%
Fesseln(USDT)
€0.88
0.01%
XRP(XRP)
€1.89
0.80%
Solana(SOL)
€135.60
-0.66%
USDC(USDC)
€0.88
0.00%
Dogecoin(DOGE)
€0.167087
0.26%
Shiba Inu(SHIB)
€0.000011
1.69%
Pepe(PEPE)
€0.000011
1.98%
Peanut das Eichhörnchen(PNUT)
€0.228236
3.13%
Nach oben scrollen