Ivanti disclosed and patched multiple vulnerabilities in Endpoint Manager (EPM), led by CVE-2024-29847, a critical unauthenticated remote code execution flaw in the Agent Portal service affecting versions prior to EPM 2022 SU6 and the 2024 September update. Ivanti rated the deserialization bug CVSS 10.0 and said it could let remote attackers execute code without authentication; the September advisory also listed additional weaknesses including XXE, multiple SQL injection flaws that could lead to RCE, authentication issues in Network Isolation and Patch Management, API secret exposure, spoofing of isolation status, and a local privilege escalation bug in the EPM agent.
Technical analysis of CVE-2024-29847 said the vulnerable Agentportal.exe service exposed a .NET Remoting TCP endpoint with a dynamically assigned port and no transport security, allowing insecure deserialization against the LANDesk.AgentPortal.IAgentPortal interface. The researcher reported that exploitation remained possible even with the .NET Remoting type filter set to Low, adapting prior techniques to bypass remoting restrictions, gain code execution, and write an ASP.NET web shell into a public IIS application directory; the writeup further claimed the compromise could be escalated from the IIS application pool context to NT AUTHORITY\SYSTEM by abusing leaked token handles in the worker process.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
A public technical writeup described how the Ivanti EPM Agent Portal .NET Remoting flaw could be exploited pre-authentication for remote code execution, including bypass techniques for the Low Type Filter and web-shell deployment details.
Ivanti published a security advisory covering multiple Endpoint Manager vulnerabilities, including CVE-2024-29847, a critical unauthenticated deserialization RCE in the Agent Portal affecting versions before 2022 SU6 or the 2024 September update.
The researcher says they reported the Ivanti Endpoint Manager Agent Portal deserialization vulnerability, later tracked as CVE-2024-29847, to Ivanti on May 1, 2024.
A researcher writeup states Ivanti later published its advisory for the patched Ivanti EPM vulnerability on September 11, 2024, identifying it as a critical CVSS 10.0 issue.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
summoning.team
Open sourceforums.ivanti.com
Open sourcesummoning.team
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.