Ivanti has released security updates to fix 13 critical security vulnerabilities in the company's Avalanche enterprise mobile device management (MDM) solution. Avalanche allows admins to manage over 100,000 mobile devices from a single, central location over the Internet, deploy software, and schedule updates. As Ivanti explained on Wednesday, these security flaws are due to WLAvalancheService stack or heap-based buffer overflow weaknesses reported by Tenable security researchers and Trend Micro's Zero Day Initiative. Unauthenticated attackers can exploit them in low-complexity attacks that don't require user interaction to gain remote code execution on unpatched systems. "An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution," Ivanti said in a security advisory. "To address the security vulnerabilities [..], it is highly recommended to download the Avalanche installer and update to the latest Avalanche 6.4.2. These vulnerabilities impact all supported versions of the products – Avalanche versions 6.3.1 and above. Older versions/releases are also at risk." The company also patched eight medium- and high-severity bugs that attackers could exploit in denial of service, remote code execution, and server-side request forgery (SSRF) attacks. All security vulnerabilities disclosed today were addressed in Avalanche v6.4.2.313. Additional information on upgrading y...
Ivanti releases patches for 13 critical Avalanche RCE flaws
BleepingComputer
·Sergiu Gatlan
·Published Dec 20, 2023
·Updated
Affected Software
2 affected components
Ivanti Avalanche=6.4.2.313
Ivanti Avalanche=6.3.1
Frequently Asked Questions
1
What is the main focus of the article?
The article discusses Ivanti's release of security patches for 13 critical remote code execution vulnerabilities in their Avalanche mobile device management solution.
2
What security implications are highlighted in the article?
The vulnerabilities could allow attackers to execute arbitrary code and gain unauthorized control over devices managed by Avalanche.
3
Which versions of software are impacted by the vulnerabilities?
The affected versions of Ivanti Avalanche are 6.4.2.313 and 6.3.1.
4
How many vulnerabilities were patched in the update?
Ivanti addressed a total of 13 critical vulnerabilities in the recent security update.
5
What is Avalanche used for?
Avalanche is used for managing over 100,000 mobile devices from a single console, enhancing enterprise mobile device management capabilities.