Jan 14, 2025 • Ivanti Security Advisories
January Security Update
Ivanti has released its January security update, addressing vulnerabilities across several key products including Ivanti Avalanche, Application Control...
Executive Summary
Ivanti has released its January security update, addressing vulnerabilities across several key products including Ivanti Avalanche, Application Control Engine, and Endpoint Manager (EPM). The vendor emphasizes its commitment to rigorous testing and transparent disclosure to empower customers to defend their environments. Crucially, Ivanti states there is currently no evidence indicating these vulnerabilities are being exploited in the wild. The vulnerabilities are isolated to the specified products and do not impact other Ivanti solutions. Customers are urged to apply the released patches immediately to mitigate potential risks. Standard security patches are released on the second Tuesday of every month to facilitate IT resource planning. Detailed remediation instructions are available via specific Security Advisories. Support is available through the Success portal for partners and customers requiring assistance. Staying updated via RSS feeds is recommended to maintain security posture against emerging threats within the Ivanti ecosystem.
Summary
Ivanti’s vulnerability management program is a central part of our commitment to security. We employ rigorous testing and validation methodologies to enable swift identification, patching, and disclosure of vulnerabilities in collaboration with the broader security ecosystem. Our priority is to provide responsible and transparent communication to our customers, so they are empowered to defend their environments. In recent months, we have intensified our internal scanning, manual exploitation and testing capabilities, and have also made enhancements to our responsible disclosure process so that we promptly discover and address potential issues, and so that our customers are best equipped to take action. As part of this, Ivanti releases standard security patches on the second Tuesday of every month. For many of our customers, the predictable schedule facilitates better planning and management of IT resources, allowing them to allocate time and personnel efficiently for the timely updates. Today, fixes have been released for the Ivanti solutions detailed below. It is important for customers to know: We have no evidence of any of these vulnerabilities being exploited in the wild. These vulnerabilities do not impact any other Ivanti products. More information on these vulnerabilities and detailed instructions on how to remediate the issues can be found in these Security Advisories: Ivanti Avalanche Ivanti Application Control Engine (AC Engine is present on Ivanti Application Control, Ivanti Neurons for App Control and can integrate with Ivanti Security Controls and Ivanti Endpoint Manager). Ivanti EPM Our Support team is always available to help customers and partners should they have any questions. Cases can be logged via the Success portal (login credentials required). Want to stay up to date on Ivanti Security Advisories? Paste https://www.ivanti.com/blog/topics/security-advisory/rss into your preferred RSS reader / functionality in your email program.
Published Analysis
Ivanti has released its January security update, addressing vulnerabilities across several key products including Ivanti Avalanche, Application Control Engine, and Endpoint Manager (EPM). The vendor emphasizes its commitment to rigorous testing and transparent disclosure to empower customers to defend their environments. Crucially, Ivanti states there is currently no evidence indicating these vulnerabilities are being exploited in the wild. The vulnerabilities are isolated to the specified products and do not impact other Ivanti solutions. Customers are urged to apply the released patches immediately to mitigate potential risks. Standard security patches are released on the second Tuesday of every month to facilitate IT resource planning. Detailed remediation instructions are available via specific Security Advisories. Support is available through the Success portal for partners and customers requiring assistance. Staying updated via RSS feeds is recommended to maintain security posture against emerging threats within the Ivanti ecosystem. Ivanti’s vulnerability management program is a central part of our commitment to security. We employ rigorous testing and validation methodologies to enable swift identification, patching, and disclosure of vulnerabilities in collaboration with the broader security ecosystem. Our priority is to provide responsible and transparent communication to our customers, so they are empowered to defend their environments. In recent months, we have intensified our internal scanning, manual exploitation and testing capabilities, and have also made enhancements to our responsible disclosure process so that we promptly discover and address potential issues, and so that our customers are best equipped to take action. As part of this, Ivanti releases standard security patches on the second Tuesday of every month. For many of our customers, the predictable schedule facilitates better planning and management of IT resources, allowing them to allocate time and personnel efficiently for the timely updates. Today, fixes have been released for the Ivanti solutions detailed below. It is important for customers to know: We have no evidence of any of these vulnerabilities being exploited in the wild. These vulnerabilities do not impact any other Ivanti products. More information on these vulnerabilities and detailed instructions on how to remediate the issues can be found in these Security Advisories: Ivanti Avalanche Ivanti Application Control Engine (AC Engine is present on Ivanti Application Control, Ivanti Neurons for App Control and can integrate with Ivanti Security Controls and Ivanti Endpoint Manager). Ivanti EPM Our Support team is always available to help customers and partners should they have any questions. Cases can be logged via the Success portal (login credentials required). Want to stay up to date on Ivanti Security Advisories? Paste https://www.ivanti.com/blog/topics/security-advisory/rss into your preferred RSS reader / functionality in your email program. Ivanti’s vulnerability management program is a central part of our commitment to security. We employ rigorous testing and validation methodologies to enable swift identification, patching, and disclosure of vulnerabilities in collaboration with the broader security ecosystem. Our priority is to provide responsible and transparent communication to our customers, so they are empowered to defend their environments. In recent months, we have intensified our internal scanning, manual exploitation and testing capabilities, and have also made enhancements to our responsible disclosure process so that we promptly discover and address potential issues, and so that our customers are best equipped to take action. As part of this, Ivanti releases standard security patches on the second Tuesday of every month. For many of our customers, the predictable schedule facilitates better planning and management of IT resources, allowing them to allocate time and personnel efficiently for the timely updates. Today, fixes have been released for the Ivanti solutions detailed below. It is important for customers to know: We have no evidence of any of these vulnerabilities being exploited in the wild. These vulnerabilities do not impact any other Ivanti products. More information on these vulnerabilities and detailed instructions on how to remediate the issues can be found in these Security Advisories: Ivanti Avalanche Ivanti Application Control Engine (AC Engine is present on Ivanti Application Control, Ivanti Neurons for App Control and can integrate with Ivanti Security Controls and Ivanti Endpoint Manager). Ivanti EPM Our Support team is always available to help customers and partners should they have any questions. Cases can be logged via the Success portal (login credentials required). Want to stay up to date on Ivanti Security Advisories? Paste https://www.ivanti.com/blog/topics/security-advisory/rss into your preferred RSS reader /...