• Menu
  • Skip to main content
  • Skip to primary sidebar

The Cyber Security News

Latest Cyber Security News

Header Right

  • Latest News
  • Vulnerabilities
  • Cloud Services
alert: ivanti discloses 2 new zero day flaws, one under active

Alert: Ivanti Discloses 2 New Zero-Day Flaws, One Under Active Exploitation

You are here: Home / General Cyber Security News / Alert: Ivanti Discloses 2 New Zero-Day Flaws, One Under Active Exploitation
January 31, 2024

Ivanti is alerting of two new substantial-severity flaws in its Connect Safe and Coverage Secure goods, a single of which is stated to have come under targeted exploitation in the wild.

The list of vulnerabilities is as follows –

  • CVE-2024-21888 (CVSS score: 8.8) – A privilege escalation vulnerability in the web element of Ivanti Connect Secure (9.x, 22.x) and Ivanti Plan Protected (9.x, 22.x) will allow a consumer to elevate privileges to that of an administrator
  • CVE-2024-21893 (CVSS rating: 8.2) – A server-facet ask for forgery vulnerability in the SAML element of Ivanti Join Safe (9.x, 22.x), Ivanti Coverage Secure (9.x, 22.x) and Ivanti Neurons for ZTA enables an attacker to entry specified restricted assets without the need of authentication

The Utah-centered application business stated it uncovered no evidence of shoppers getting impacted by CVE-2024-21888 so far, but acknowledged “the exploitation of CVE-2024-21893 seems to be qualified.”

✔ Approved From Our Partners
AOMEI Backupper Lifetime

Protect and backup your data using AOMEI Backupper. AOMEI Backupper takes secure and encrypted backups from your Windows, hard drives or partitions. With AOMEI Backupper you will never be worried about loosing your data anymore.

Get AOMEI Backupper with 72% discount from an authorized distrinutor of AOMEI: SerialCart® (Limited Offer).

➤ Activate Your Coupon Code


Cybersecurity

It further more mentioned that it “expects the risk actor to modify their actions and we be expecting a sharp raise in exploitation once this data is community.”

In tandem to the public disclosure of the two new vulnerabilities, Ivanti has released fixes for Link Protected versions 9.1R14.4, 9.1R17.2, 9.1R18.3, 22.4R2.2 and 22.5R1.1, and ZTA model 22.6R1.3.

“Out of an abundance of caution, we are recommending as a best exercise that buyers manufacturing unit reset their appliance ahead of applying the patch to reduce the menace actor from gaining improve persistence in your natural environment,” it claimed. “Buyers should really assume this approach to take 3-4 hrs.”

As momentary workarounds to address CVE-2024-21888 and CVE-2024-21893, users are recommended to import the “mitigation.release.20240126.5.xml” file.

The most current progress comes as two other flaws in the similar products – CVE-2023-46805 and CVE-2024-21887 – have arrive beneath broad exploitation by several menace actors to deploy backdoors, cryptocurrency miners, and a Rust-based mostly loader termed KrustyLoader.

Identified this report intriguing? Stick to us on Twitter  and LinkedIn to read additional distinctive information we publish.


Some areas of this post are sourced from:
thehackernews.com

Previous Post: «telegram marketplaces fuel phishing attacks with easy to use kits and malware Telegram Marketplaces Fuel Phishing Attacks with Easy-to-Use Kits and Malware
Next Post: RunC Flaws Enable Container Escapes, Granting Attackers Host Access runc flaws enable container escapes, granting attackers host access»

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

Report This Article

Recent Posts

  • Zero-Click Agentic Browser Attack Can Delete Entire Google Drive Using Crafted Emails
  • Critical XXE Bug CVE-2025-66516 (CVSS 10.0) Hits Apache Tika, Requires Urgent Patch
  • Chinese Hackers Have Started Exploiting the Newly Disclosed React2Shell Vulnerability
  • Intellexa Leaks Reveal Zero-Days and Ads-Based Vector for Predator Spyware Delivery
  • “Getting to Yes”: An Anti-Sales Guide for MSPs
  • CISA Reports PRC Hackers Using BRICKSTORM for Long-Term Access in U.S. Systems
  • JPCERT Confirms Active Command Injection Attacks on Array AG Gateways
  • Silver Fox Uses Fake Microsoft Teams Installer to Spread ValleyRAT Malware in China
  • ThreatsDay Bulletin: Wi-Fi Hack, npm Worm, DeFi Theft, Phishing Blasts— and 15 More Stories
  • 5 Threats That Reshaped Web Security This Year [2025]

Copyright © TheCyberSecurity.News, All Rights Reserved.