
Ivanti has released fixes for more than two dozen vulnerabilities plaguing its Avalanche mobile device management (MDM) offering, including for two critical severity flaws that could be abused to execute code remotely.
In the accompanying security advisory Avalanche said the two flaws are tracked as CVE-2024-24996, and CVE-2024-29204. Both are described as heap-based buffer overflow bugs, allowing unauthenticated remote threat actors to trigger arbitrary commands on vulnerable endpoints. The attacks are low in complexity and don’t need any interaction on the victim’s side.