Cyber Posture

CVE-2024-13167

High

Published: 14 January 2025

Published
14 January 2025
Modified
11 July 2025
KEV Added
Patch
CVSS Score 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS Score 0.0153 81.4th percentile
Risk Priority 16 60% EPSS · 20% KEV · 20% CVSS

Description

An out-of-bounds write in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to cause a denial of service.

Security Summary

CVE-2024-13167 is an out-of-bounds write vulnerability affecting Ivanti Endpoint Manager (EPM) versions prior to the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update. This flaw, classified under CWE-787, enables memory corruption due to improper bounds checking in a specific component of the software.

A remote unauthenticated attacker can exploit this vulnerability over the network with low complexity and no privileges required, as indicated by its CVSS v3.1 base score of 7.5 (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Successful exploitation leads to a denial-of-service condition, potentially crashing the affected EPM instance and disrupting endpoint management services without impacting confidentiality or integrity.

Ivanti's security advisory for this issue, available at https://forums.ivanti.com/s/article/Security-Advisory-EPM-January-2025-for-EPM-2024-and-EPM-2022-SU6, recommends applying the January-2025 Security Updates for EPM 2024 and EPM 2022 SU6 to mitigate the vulnerability. Organizations should prioritize patching exposed EPM instances to prevent exploitation.

Details

CWE(s)
CWE-787

Affected Products

ivanti
endpoint manager
2022, 2024 · ≤ 2022

References