EXPOSURES › CVE-2021-44529
CVE-2021-44529
CRITICAL ⌖ ON CISA KEV · EXPLOITEDAn unauthenticated code injection flaw in Ivanti's Endpoint Manager Cloud Service Appliance allowed attackers to execute malicious code, directly enabling ransomware campaigns.
Ivanti's Endpoint Manager Cloud Service Appliance (EPM CSA) suffered a critical code injection vulnerability (CVE-2021-44529) that allowed unauthenticated attackers to execute malicious code with limited permissions. This failure is highly relevant to DIB organizations because the vulnerability was actively exploited in the wild and linked to ransomware attacks, meaning unpatched systems faced immediate compromise. DIB orgs must ensure all Ivanti EPM CSA instances are patched and monitored for signs of exploitation, as the flaw bypassed authentication entirely.
Shame score — The vulnerability was unauthenticated, actively exploited in the wild, and directly linked to ransomware, representing a severe, avoidable failure in securing a widely deployed endpoint management platform.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Ivanti Endpoint Manager Cloud Service Appliance (EPM CSA) contains a code injection vulnerability that allows an unauthenticated user to execute malicious code with limited permissions (nobody).
| PRODUCT | STATUS |
|---|---|
| Ivanti Neurons for ITSM (Formerly Service Manager) Ivanti |
Authorized |
| Ivanti Neurons for MDM (Formerly MobileIron) Ivanti |
Authorized |