Skip to content
COOEY

EXPOSURES › CVE-2021-44529

CVE-2021-44529

CRITICAL ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2024-03-25 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2021-44529 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 85/100 ransomwarerceexploited-in-wildunpatched

An unauthenticated code injection flaw in Ivanti's Endpoint Manager Cloud Service Appliance allowed attackers to execute malicious code, directly enabling ransomware campaigns.

Ivanti's Endpoint Manager Cloud Service Appliance (EPM CSA) suffered a critical code injection vulnerability (CVE-2021-44529) that allowed unauthenticated attackers to execute malicious code with limited permissions. This failure is highly relevant to DIB organizations because the vulnerability was actively exploited in the wild and linked to ransomware attacks, meaning unpatched systems faced immediate compromise. DIB orgs must ensure all Ivanti EPM CSA instances are patched and monitored for signs of exploitation, as the flaw bypassed authentication entirely.

Shame score — The vulnerability was unauthenticated, actively exploited in the wild, and directly linked to ransomware, representing a severe, avoidable failure in securing a widely deployed endpoint management platform.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Ivanti Endpoint Manager Cloud Service Appliance (EPM CSA) contains a code injection vulnerability that allows an unauthenticated user to execute malicious code with limited permissions (nobody).

AFFECTED FEDRAMP PRODUCTS · 2
PRODUCTSTATUS
Ivanti Neurons for ITSM (Formerly Service Manager)
Ivanti
Authorized
Ivanti Neurons for MDM (Formerly MobileIron)
Ivanti
Authorized