Ivanti has released security updates to fix 13 critical security vulnerabilities in the company's Avalanche enterprise mobile device management solution.
Avalanche allows admins to manage over 100,000 mobile devices from a single, central location over the Internet, deploy software, and schedule updates.
As Ivanti explained on Wednesday, these security flaws are due to WLAvalancheService stack or heap-based buffer overflow weaknesses reported by Tenable security researchers and Trend Micro's Zero Day Initiative.
Unauthenticated attackers can exploit them in low-complexity attacks that don't require user interaction to gain remote code execution on unpatched systems.
The company also patched eight medium- and high-severity bugs that attackers could exploit in denial of service, remote code execution, and server-side request forgery attacks.
All security vulnerabilities disclosed today were addressed in Avalanche v6.4.2.313.
Additional information on upgrading your Avalanche installation is available in this Ivanti support article.
In August, Ivanti fixed two other critical Avalanche buffer overflows tracked collectively as CVE-2023-32560 that could lead to crashes and arbitrary code execution following successful exploitation.
Threat actors chained a third MobileIron Core zero-day with CVE-2023-35078 to hack into the IT systems of a dozen Norwegian ministries one month earlier.
Four months earlier, in April, state-affiliated hackers used two other zero-day flaws in Ivanti's Endpoint Manager Mobile, formerly MobileIron Core, to infiltrate the networks of multiple Norwegian government organizations.
Microsoft discovers critical RCE flaw in Perforce Helix Core Server.
Hackers are exploiting critical Apache Struts flaw using public PoC. Sophos backports RCE fix after attacks on unsupported firewalls.
WordPress fixes POP chain exposing websites to RCE attacks.
50K WordPress sites exposed to RCE attacks by critical bug in backup plugin.
This Cyber News was published on www.bleepingcomputer.com. Publication date: Wed, 20 Dec 2023 18:05:07 +0000