YoVDO

Finding a Three 0-Day Exploit Chain in Ivanti EPMM and Ivanti Sentry

Offered By: NDC Conferences via YouTube

Tags

Vulnerability Analysis Courses Cybersecurity Courses Authentication Bypass Courses

Course Description

Overview

Save Big on Coursera Plus. 7,000+ courses at $160 off. Limited Time Only!
Explore a detailed analysis of three critical 0-day vulnerabilities discovered in Ivanti Endpoint Protection Manager Mobile (EPMM) and Ivanti Sentry during the summer of 2023. Delve into the technical aspects of CVE-2023-35078, an authentication bypass in Ivanti EPMM with a CVSS score of 9.8; CVE-2023-35081, a path traversal and arbitrary file write vulnerability in Ivanti EPMM with a CVSS score of 7.2; and CVE-2023-38035, an authentication bypass in Ivanti Sentry with a CVSS score of 9.8 that allows command execution as root. Gain insights into how these vulnerabilities can be combined into an exploit chain, their inclusion in CISA's Known Exploited Vulnerabilities catalog, and their confirmed exploitation by threat actors in the wild. Uncover the technical details and implications of these security flaws in this comprehensive 58-minute conference talk recorded at NDC Security in Oslo, Norway.

Syllabus

Finding a three 0-day exploit chain in Ivanti EPMM and Ivanti Sentry - Tor E. Bjørstad


Taught by

NDC Conferences

Related Courses

ConnectWise ScreenConnect Vulnerability: What You Should Know
Pluralsight
Ivanti Connect Secure VPN Vulnerability: What You Should Know
Pluralsight
Attacking ADFS Endpoints with PowerShell
YouTube
Owning the Message Oriented Middleware - Security Analysis and Attacks
OWASP Foundation via YouTube
Breaking Bad Multifactor - MFA Bypasses and How to Assess the Risks
Security BSides London via YouTube