Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2024-13166

CVE-2024-13166: Ivanti Endpoint Manager DoS Vulnerability

CVE-2024-13166 is a denial of service vulnerability in Ivanti Endpoint Manager caused by an out-of-bounds write flaw. Remote unauthenticated attackers can exploit this to disrupt services. This article covers technical details, affected versions, impact, and mitigation strategies.

Published:

CVE-2024-13166 Overview

CVE-2024-13166 is an out-of-bounds write vulnerability [CWE-787] affecting Ivanti Endpoint Manager (EPM). The flaw exists in EPM versions prior to the 2024 January-2025 Security Update and the 2022 SU6 January-2025 Security Update. A remote unauthenticated attacker can exploit the vulnerability over the network to trigger a denial of service condition. Ivanti disclosed the issue in its January 2025 Security Advisory and released patches the same month. The vulnerability does not require authentication or user interaction, lowering the barrier for exploitation against exposed EPM deployments.

Critical Impact

Remote unauthenticated attackers can crash the Ivanti EPM service over the network, disrupting endpoint management operations for enterprises that rely on EPM for software distribution, patching, and asset management.

Affected Products

  • Ivanti Endpoint Manager 2024 (prior to January-2025 Security Update)
  • Ivanti Endpoint Manager 2022 SU1 through SU5
  • Ivanti Endpoint Manager 2022 SU6 (prior to January-2025 Security Update)

Discovery Timeline

  • 2025-01-14 - CVE-2024-13166 published to the National Vulnerability Database (NVD)
  • 2025-01-14 - Ivanti releases the January 2025 Security Advisory and patches for EPM 2024 and EPM 2022 SU6
  • 2025-07-11 - Last updated in the NVD database

Technical Details for CVE-2024-13166

Vulnerability Analysis

The vulnerability is an out-of-bounds write that occurs when Ivanti EPM processes network-sourced input. Out-of-bounds write conditions arise when software writes data past the end, or before the beginning, of an allocated buffer. In this case, the corrupted memory region causes the affected EPM service to terminate, producing a denial of service. The impact is limited to availability — confidentiality and integrity of data handled by EPM are not affected based on the published CVSS vector. Because EPM acts as the central management plane for endpoints, an outage prevents administrators from distributing software, applying patches, or collecting inventory data until the service is restored.

Root Cause

The underlying weakness is classified as [CWE-787: Out-of-bounds Write]. Ivanti has not publicly disclosed the specific component, function, or input-handling path affected. The fix is delivered through the EPM 2024 January-2025 Security Update and EPM 2022 SU6 January-2025 Security Update, which correct boundary validation in the vulnerable code path.

Attack Vector

The attack vector is network-based. An unauthenticated remote attacker sends crafted input to a network-exposed EPM service to trigger the out-of-bounds write. No privileges or user interaction are required. Exploitation produces a denial of service rather than code execution, but successful attacks disrupt management capability across all endpoints managed by the affected EPM instance.

No public proof-of-concept exploit is currently available, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. Refer to the Ivanti Security Advisory January 2025 for vendor-supplied technical details.

Detection Methods for CVE-2024-13166

Indicators of Compromise

  • Unexpected termination, crash, or restart of Ivanti EPM service processes on the management server
  • Gaps in EPM-generated logs, agent check-ins, or scheduled task execution that align with inbound network activity
  • Crash dumps or Windows Application event log entries referencing EPM components during periods of anomalous network traffic

Detection Strategies

  • Monitor EPM server availability and service uptime to identify abnormal crash patterns characteristic of exploitation attempts
  • Inspect network traffic to EPM listening ports for malformed or unusually large requests originating from untrusted sources
  • Correlate EPM service restarts with firewall and IDS logs to identify the source of triggering network packets

Monitoring Recommendations

  • Enable verbose logging on the EPM server and forward logs to a centralized SIEM for alerting on service crashes
  • Track the EPM server with availability monitoring tools that alert on repeated service failures within short time windows
  • Alert on inbound connections to EPM management ports from IP addresses outside the expected administrative network ranges

How to Mitigate CVE-2024-13166

Immediate Actions Required

  • Inventory all Ivanti EPM deployments and identify instances running EPM 2024 or EPM 2022 SU6 without the January 2025 Security Update applied
  • Apply the EPM 2024 January-2025 Security Update or EPM 2022 SU6 January-2025 Security Update as soon as a maintenance window permits
  • Restrict network access to EPM management interfaces using firewall rules so that only authorized administrative networks can reach the service
  • Review EPM server logs and crash history for evidence of prior exploitation attempts

Patch Information

Ivanti released fixes in the January 2025 Security Advisory. Administrators should upgrade to Ivanti Endpoint Manager 2024 with the January-2025 Security Update applied, or Ivanti Endpoint Manager 2022 SU6 with the January-2025 Security Update applied. Full details are available in the Ivanti Security Advisory January 2025.

Workarounds

  • Place EPM servers behind a VPN or jump host so that the management service is not reachable from untrusted networks
  • Apply network segmentation to isolate EPM infrastructure from general user and internet-facing subnets
  • Implement strict ingress filtering at perimeter firewalls to drop unsolicited traffic destined for EPM service ports

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.