#AgentPortal
CVE-2024-29847 Deep Dive: Ivanti Endpoint Manager AgentPortal Deserialization of Untrusted Data Remote Code Execution Vulnerability – Horizon3.ai
CVE-2024-29847 Deep Dive: Ivanti Endpoint Manager AgentPortal Deserialization of Untrusted Data Remote Code Execution Vulnerability – Horizon3.ai
www.horizon3.ai
September 13, 2024 at 3:24 PM
CVE-2024-29847 Deep Dive: Ivanti Endpoint Manager AgentPortal Deserialization of Untrusted Data Remote Code Execution Vulnerability

https://www.horizon3.ai/attack-research/attack-blogs/cve-2024-29847-deep-dive-ivanti-endpoint-manager-agentportal-deseri...


Original post
September 13, 2024 at 5:22 PM
ZDI、Ivanti Endpoint Managerの未修正脆弱性13件を公開

トレンドマイクロのZero Day Initiative(ZDI)は今週、Ivanti Endpoint Managerに存在する未修正の脆弱性13件に関するアドバイザリを公開しました。 これらの脆弱性のうち1件はローカル攻撃者による権限昇格を可能にし、2024年11月にIvantiへ報告されました。残りの12件はリモートコード実行(RCE)につながるもので、2025年6月に報告されました。…
ZDI、Ivanti Endpoint Managerの未修正脆弱性13件を公開
トレンドマイクロのZero Day Initiative(ZDI)は今週、Ivanti Endpoint Managerに存在する未修正の脆弱性13件に関するアドバイザリを公開しました。 これらの脆弱性のうち1件はローカル攻撃者による権限昇格を可能にし、2024年11月にIvantiへ報告されました。残りの12件はリモートコード実行(RCE)につながるもので、2025年6月に報告されました。 これらの脆弱性は技術的にはゼロデイではありませんが、ZDIは公開する未修正の脆弱性すべてを「0day」としています。ZDIのアドバイザリでは、脆弱なコンポーネントの名称と根本原因の一般的な説明が記載されていますが、その他の技術的な詳細は含まれていません。 これらの脆弱性にはCVE識別子は発行されていませんが、ZDIはすべてが高深刻度の欠陥であると指摘しています。最も深刻なものはCVSSスコア8.8、1件は7.8、残りの11件は7.2のCVSSスコアとなっています。 ZDIによると、ローカル権限昇格のバグはEndpoint ManagerのAgentPortalサービスに影響します。これは、ユーザーから提供された入力が適切に検証されていないために発生し、信頼できないデータのデシリアライズとSystem権限でのコード実行につながります。 また、ユーザーから提供されたデータの適切な検証が行われていないことに起因するRCEの脆弱性は、製品のReport_RunPatch、MP_Report_Run2、DBDR、PatchHistory、MP_QueryDetail2、MP_QueryDetail、MP_VistaReport、Report_Runの各クラス、およびGetCountForQueryとOnSaveToDBメソッドで発見されました。 最初の11件のRCE脆弱性では、適切に検証されていないユーザー入力がSQLクエリの構築に使用され、サービスアカウントのコンテキストで任意のコード実行につながる可能性があります。これらを悪用するには認証が必要です。 最後のRCE問題(CVSSスコア8.8)では、適切に検証されていないユーザー指定のパスがファイル操作に使用され、ユーザーのコンテキストでコード実行が可能となります。攻撃者は管理者資格情報を持っている場合や、ユーザーに悪意あるページやファイルを開かせることができれば、この欠陥を悪用できます。 ZDIによると、Ivantiは最初のセキュリティホールについて2024年11月に通知を受け、2025年1月に認識しました。7月には、ベンダーからZDIに対し、パッチは11月にリリースされると通知がありました。 RCE脆弱性については、Ivantiは当初10件を9月に修正するとしていましたが、その後、12件すべてについて2026年3月までの延長を求めたとZDIは述べています。 ZDIの開示ポリシーによれば、ベンダーには報告から120日間の対応期間が与えられます。期限までにベンダーが応答しない、または修正がリリースされていない合理的な理由を示さない場合、ZDIは報告されたセキュリティ欠陥について限定的なアドバイザリを公開します。 「脆弱性の性質を考慮すると、唯一有効な緩和策は製品とのやり取りを制限することです」とZDIは各バグについて述べています。追加情報はZDIの公開アドバイザリページで確認できます。 なぜIvantiが開示期間内にこれらのバグに対するパッチを提供できていないのかは不明です。同社はまだアドバイザリを公開していません。SecurityWeekは本件についてIvantiにコメントを求めており、ベンダーから回答があれば本記事を更新します。 関連記事: 中国のスパイが重要分野に対するIvantiの脆弱性を悪用 翻訳元:
blackhatnews.tokyo
October 10, 2025 at 9:48 AM
Early birds get the best tools!

ProSuite members get first access to NorbieLink. Get Global Search, AI Appetite Search, smoother endorsements, and stronger admin + MFA security.

Subscribe to ProSuite to get in early.
https://loom.ly/2JfWfLo

#NorbieLink #ProSuite #BTISAgents #AgentPortal
June 8, 2026 at 4:04 PM
ProSuite members are first in line for NorbieLink, BTIS’s next generation agent portal.

Get faster search, smarter appetite matching, and cleaner endorsements.

What would save you the most time: search, appetite, or endorsements?
https://loom.ly/qhUfXSE

#NorbieLink #ProSuite #AgentPortal
June 1, 2026 at 4:05 PM
This week’s NorbieLink feedback is all about staying in control: sort what matters fast, update team access quickly, and keep endorsements moving without losing track.

Which part of your day would you want to feel this smooth?
https://loom.ly/6LSjCUI

#NorbieLink #BTISAgents #AgentPortal
May 26, 2026 at 4:05 PM
NorbieLink is here! ProSuite members get early access. Subscribe to try it!

Agents, what would you look for first in a new portal?

https://loom.ly/OwCZpSU
#NorbieLink #ProSuite #BTISAgents #AgentPortal #InsuranceAgents
May 22, 2026 at 4:04 PM
Agents are loving NorbieLink so far: faster workflows, easier follow-ups, and small time-savers that add up.

What kind of win would make the biggest difference for you this week?
https://loom.ly/2Bd7lbQ

#NorbieLink #BTISAgents #InsuranceAgents #AgentPortal #InsuranceTech
May 19, 2026 at 4:05 PM
We’ve been gathering agent feedback on NorbieLink, and it’s clear: less searching, fewer steps, and a smoother day overall.

If one part of your day could get simpler overnight, what would you pick?

https://loom.ly/p9vcN4g

#NorbieLink #BTISAgents #InsuranceAgents #AgentPortal #InsuranceTech
May 15, 2026 at 9:01 PM
Curious what’s inside NorbieLink?

ProSuite members get access to faster search, AI appetite matching, and streamlined workflows.

Which feature would save you the most time? Subscribe for access!
https://loom.ly/k7KBBKQ

#NorbieLink #ProSuite #BTISAgents #AgentPortal #InsuranceTech #NewTools
May 13, 2026 at 4:05 PM
NorbieLink is almost here.

We’ve been working behind the scenes to deliver our best agent experience yet. Smoother, faster, and built to make your day easier from the moment you log in.

Big updates are coming. Stay tuned.
https://loom.ly/iYHmRHU

#NorbieLink #ComingSoon #BTISAgents #AgentPortal
April 21, 2026 at 4:05 PM
A portal built for how you actually work. 🚀

Designed around your workflow. Engineered for your success. Built to transform your everyday.

The future is closer than you think.

NorbieLink. Dropping 2026.

#NorbieLink #AgentPortal #BuiltForYou #WorkflowRevolution #InsuranceTech
February 26, 2026 at 5:04 PM
Horizon3.ai Exploit Developer James Horseman has just published “CVE-2024-29847 Deep Dive: Ivanti Endpoint Manager AgentPortal Deserialization of Untrusted Data Remote Code Execution Vulnerability” and posted a proof of concept exploit. “Ivanti Endpoint Manager... https://wp.me/pcmht-ujP
September 14, 2024 at 12:58 PM