Vulnerabilities

Ivanti Patches Critical Vulnerability in Avalanche Enterprise MDM Solution

Ivanti has patched critical- and high-severity vulnerabilities with the latest release of Avalanche, its enterprise mobile device management solution.

Ivanti vulnerability

Ivanti has released patches for seven critical- and high-severity vulnerabilities in Avalanche, its enterprise mobile device management (MDM) solution.

The most severe of the flaws is CVE-2023-32563 (CVSS score of 9.8), a directory traversal bug that can be exploited to execute arbitrary code remotely.

Reported by security researchers with Trend Micro’s ZDI, the issue exists in the ‘updateSkin’ method of the MDM solution and can be exploited without authentication.

“The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to execute code in the context of System,” ZDI’s advisory reads.

The latest Avalanche iteration also resolves multiple stack-based buffer overflow bugs that are collectively tracked as CVE-2023-32560 (CVSS score of 8.8).

The vulnerability resides in Wavelink Avalanche Manager, which uses a fixed-size stack-based buffer when processing certain types of data, explained Tenable, whose researchers discovered the issue.

Advertisement. Scroll to continue reading.

An unauthenticated, remote attacker can trigger the vulnerability by sending a crafted message to the service, which could lead to service disruption or code execution.

Two other high-severity remote code execution vulnerabilities were patched with the latest Avalanche release, both discovered and reported through ZDI.

The flaws, CVE-2023-32562 and CVE-2023-32564, are the result of a “lack of proper validation of user-supplied data”, allowing an attacker to upload arbitrary files and potentially execute code with System privileges.

All three remaining vulnerabilities – CVE-2023-32561, CVE-2023-32565, and CVE-2023-32566 – are described as authentication bypass flaws in various components of the MDM solution.

Ivanti patched all seven vulnerabilities in Avalanche version 6.4.1.207, which was released earlier this month. Both Tenable and ZDI, however, released details on these vulnerabilities only this week.

While there’s no mention of any of these issues being exploited in the wild, vulnerabilities in Ivanti products are known to have been targeted in malicious attacks.

Related: Exploitation of Ivanti EPMM Flaw Picking Up as New Vulnerability Is Disclosed

Related: Ivanti Zero-Day Vulnerability Exploited in Attack on Norwegian Government

Related: Five Eyes Agencies Call Attention to Most Frequently Exploited Vulnerabilities

Related Content

Vulnerabilities

A critical security defect in the ServiceNow AI platform could allow remote attackers to execute arbitrary code.

Vulnerabilities

The critical-severity OS command injection vulnerability allows attackers to execute arbitrary code with root privileges.

Vulnerabilities

Two OS command injection flaws can be exploited remotely, without authentication, for arbitrary code execution.

Vulnerabilities

Successful exploitation of these flaws could lead to arbitrary code execution and information disclosure.

Vulnerabilities

CVE-2026-6973 is a high-severity vulnerability that allows an attacker who has admin privileges to execute arbitrary code.

Vulnerabilities

The flaws could allow a remote attacker to maintain access after their account has been disabled and to access information from other user sessions.

Vulnerabilities

The bugs could lead to arbitrary code execution, privilege escalation, or authentication rate-limit bypass.

Malware & Threats

Security researchers have seen the vulnerabilities being exploited to deliver shells, conduct reconnaissance, and download malware.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version