LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2021-44529: Ivanti Endpoint Manager Cloud Service Appliance (EPM CSA) Code Injection Vulnerability

RBRecent Breaches Vulnerability Intelligence·Mar 25, 2024
Critical⚠ Actively exploited (CISA KEV)Ransomware-linked
Critical
Severity
Active
CISA KEV
Yes
Ransomware use
Apr 15, 2024
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2021-44529 to its Known Exploited Vulnerabilities catalog on Mar 25, 2024, with a federal patch deadline of Apr 15, 2024 — meaning attackers are actively using it. If you run the affected software, patch it immediately. Ransomware crews are known to exploit this flaw.

Ivanti Endpoint Manager Cloud Service Appliance (EPM CSA) contains a code injection vulnerability that allows an unauthenticated user to execute malicious code with limited permissions (nobody).

CVE-2021-44529 is a code injection vulnerability in the Ivanti Endpoint Manager Cloud Service Appliance (EPM CSA). It allows an unauthenticated attacker to execute malicious code under limited permissions (the nobody account). Because this product often sits in management and endpoint infrastructure, successful abuse can give attackers a foothold for further movement or ransomware activity. CISA has noted known ransomware use of this vulnerability, so organizations running EPM CSA should treat it as high priority and confirm all details against the vendor advisory.

How it works

The underlying weakness is CWE-94, improper control of code generation (code injection). In this class of flaw, the application accepts input that is later interpreted or executed as code without sufficient validation or sanitization. An unauthenticated user can supply crafted input that causes the EPM CSA to run attacker-controlled code. The CISA summary states that the resulting execution occurs with limited permissions (nobody), which still provides a useful initial foothold. From there an attacker may attempt privilege escalation, lateral movement, or deployment of additional payloads. Exact request formats, endpoints, or payload construction are not detailed here; defenders must obtain those from the vendor advisory and any accompanying technical analysis rather than relying on incomplete public descriptions.

Am I affected? How to find it in your systems

Ivanti Endpoint Manager Cloud Service Appliance is typically deployed as a dedicated appliance or virtual machine that supports endpoint management, inventory, and related cloud-service functions. It is commonly found in enterprise networks that use Ivanti EPM for device management. Inventory steps include:

For signs of exploitation, examine appliance logs, web-server access logs, and any process-execution telemetry for unexpected activity under the nobody account or anomalous code-execution patterns. Correlate with network traffic to the management interface. Because public detail on specific indicators is limited, treat any unexplained process launches or configuration changes as suspicious and investigate against the vendor’s guidance.

How to remediate

Patch first. Apply the vendor update or mitigation instructions named in the official Ivanti advisory for CVE-2021-44529. CISA’s required action is to apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. After patching:

Document the change and re-scan to confirm the vulnerability is no longer present.

If you can't patch immediately

Until the vendor update can be applied, reduce exposure with compensating controls:

These steps lower the chance of successful exploitation but do not replace the permanent fix.

If your data may have been exposed

Actively exploited vulnerabilities, including those with known ransomware use, frequently lead to data theft or encryption. If you believe your EPM CSA instance was compromised, isolate the system, preserve logs and forensic images, and begin incident-response procedures. Review any credentials, endpoint data, or configuration information that the appliance could have accessed. As a quick additional check, individuals can run a free exposure scan of their work email addresses against known breach data sets to see whether those addresses appear in public breach compilations; organizational teams should also search internal breach-notification and dark-web monitoring sources for related indicators.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedIvanti · Endpoint Manager Cloud Service Appliance (EPM CSA)
WeaknessCWE-94
Added to CISA KEVMar 25, 2024
Federal patch deadlineApr 15, 2024
Known ransomware useYes
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities