¡¾¸´ÏÖ¡¿Ivanti Endpoint Manager MobileÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2026-1281ºÍCVE-2026-1340£©

°ä²¼¹¦·ò 2026-02-03

Ivanti Endpoint Manager Mobile(EPMM) £¬Ô­ÃûMobileIron Core £¬ÊÇÈ«Çòµ±ÏÈµÄÆóÒµ¼¶Í³Ò»¶ËµãÖÎÀí£¨UEM£©Æ½Ì¨¡£


2026Äê1ÔÂ29ÈÕ £¬Ivanti°ä²¼¸üÐÂÐÞ¸´ÁËIvanti Endpoint Manager MobileÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2026-1281ºÍCVE-2026-1340£© £¬CVSSÆÀ·Ö9.8·Ö£¨ÑÏÖØ£©¡£ÎÊÌâ³öÔÚIvanti EPMMÔÚ´¦ÖÃÌØ¶¨URLʱ £¬Apache»áͨ¹ýRewriteMapÖ°Äܽ«URLÖеIJÎÊýÖ±½Ó´«µÝ¸øºó¶ËµÄBash¾ç±¾Ö´ÐС£¹¥»÷ÕßÔڿɿصÄ×Ö·û´®´øÈëÁËËãÊõÀ©´ó¸ßµÍÎÄ £¬µ¼Ö BashµÝ¹é½âÎö±äÁ¿Ãû²¢´¥·¢ÁË·´ÒýºÅÖеĶñÒâºÅÁî¡£


ƾ¾Ý¹¥»÷ÃæÖÎÀíÆ½Ì¨ Censys µÄÊý¾Ý £¬½ØÖÁ 2026 Äê2 Ô 2 ÈÕ £¬»¥ÁªÍøÉÏ´æÔÚ529¸öDZÔÚµÄÒ×Êܹ¥»÷Ivanti Endpoint Manager MobileʵÀý¡£ÓÉÓÚ¸ÅÄîÑéÖ¤·ì϶ÀûÓ÷¨Ê½ÒѾ­°ä²¼ £¬²¢ÇҸ÷ì϶ÒÑÔÚ»¥ÁªÍøÉÏ¿í·º´«²¼ £¬Òò¶ø¶ÔÓÚʹÓÃIvanti Endpoint Manager MobileµÄ×éÖ¯¶øÑÔ £¬¸Ã·ì϶×é³ÉÁËÖ±½ÓÇÒÑÏÖØµÄ·çÏÕ¡£


·ì϶ÃèÊö


ÔÚIvanti Endpoint Manager MobileϵͳÖÐ £¬¸ÃϵͳµÄApache RewriteMapÅäÖÃÖÐÓÉÓû§ÌṩµÄÊäÈë´«µÝ¸øBash¾ç±¾Ö´ÐС£º£Ö÷Ìⰲȫ·ì϶ÊÇÒ»¸öBashËãÊõÀ©´ó×¢Èë·ì϶ £¬ÔÊÐíδ¾­Éí·ÝÑéÖ¤µÄ¹¥»÷ÕßÖ´ÐÐËÁÒâϵͳºÅÁî¡£¾ßÌåÀ´Ëµ£º£º


    ? Ivanti Endpoint Manager MobileÖ±½Ó½«URLÖРsha256: ºóµÄÓû§ÊäÈë´«µÝ¸øBash¾ç±¾ £¬×÷ΪÂß¼­ÅжϵıäÁ¿ £¬²»×ãÓÐЧµÄתÒå»ò¹ýÂË¡£

    ? ¾ç±¾ÄÚ²¿µÄËãÊõ±ÈÁ¦Ä£¿é(( )) ´æÔڵݹé½âÎö¸öÐÔ £¬¹¥»÷ÕßÀûÓñäÁ¿¼äµÄǶÌ×ÒýÓÃʵÏÖÔ¶³Ì´úÂëÖ´ÐС£


Ivanti¹Ù·½ÃèÊöΪ£º£ºA code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.


Ó°ÏìÁìÓò


Ivanti Endpoint Manager Mobile < =12.5.0.0

Ivanti Endpoint Manager Mobile < =12.5.1.0

Ivanti Endpoint Manager Mobile < =12.6.0.0

Ivanti Endpoint Manager Mobile < =12.6.1.0

Ivanti Endpoint Manager Mobile < =12.7.0.0


·ì϶µÀÀí


·ì϶ԴÓÚApache HTTPdÅäÖÃÁËRewriteMap£¨mapAppStoreURL ºÍ mapAftStoreURL£© £¬Ö±½Ó½«Î´¾­¹ýÂ˵ÄURL²ÎÊý´«µÝ¸øµ×²ãµÄBash¾ç±¾ £¬´¥·¢õ辶Ϊ /mifs/c/appstore/fob/3/... £¬¸Ãõè¾¶²»±ØÒªÈκÎÉí·ÝÑéÖ¤ £¬´úÂëÈçÏ£º£º


    RewriteRule ^/mifs/c/appstore/fob/3/([0-9]+)/sha256:(.*)/(.*)(.ipa)$ ${mapAppStoreURL:$2_$1_$3_$4_%{HTTP_HOST}_%{ENV:SCRIPT_URL}} [T=application/octet-stream,UnsafePrefixStat]


    ¹¥»÷ÕßÄܹ»Í¨¹ý½ÚÖÆsha256:kid=... ºóÃæµÄ×Ö·û´® £¬½«¶ñÒâºÅÁî×¢Èëµ½Bash¾ç±¾´¦ÖÃÁ÷³ÌÖÐ £¬¾ç±¾õè¾¶£º£º/mi/bin/map-appstore-url £¬´úÂëÈçÏ£º£º


    ͼƬ1.png


    ·ì϶¸´ÏÖ


    ÔÚyakitÖз¢ËÍPOC £¬Ö´ÐÐping dnslogºÅÁî¡£


    ͼƬ2.png


    ½Ó¹Üµ½dnslogÑéÖ¤ £¬¼´ping dnslogºÅÁîÖ´Ðгɹ¦¡£


    ͼƬ3.png


    °²È«½¨Òé


      £¨1£©Á¢¼´Éý¼¶

      Ivanti Endpoint Manager Mobile¹Ù·½ÒѰ䲼°²È«²¼¸æ £¬Çë°´Áìµ¼½øÐÐÐÞ¸´¡£


      £¨2£©Ò»Ê±»º½â´ëÊ©

      ÀûÓÃһʱRPM²¹¶¡£º£º

      ? ºÏÓÃÓÚ12.5.0.x¡¢¡¢¡¢12.6.0.x¡¢¡¢¡¢12.7.0.x°æ±¾£º£ºinstall rpm url 

      https://username:password@support.mobileiron.com/mi/vsp/AB1771634/ivanti-security-update-1761642-1.0.0S-5.noarch.rpm

      ºÏÓÃÓÚ12.5.1.0ºÍ12.6.1.0°æ±¾£º£ºinstall rpm url

      https://username:password@support.mobileiron.com/mi/vsp/AB1771634/ivanti-security-update-1761642-1.0.0L-5.noarch.rpm


      ²Î¿¼Á´½Ó£º£º


      [1]https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Endpoint-Manager-Mobile-EPMM-CVE-2026-1281-CVE-2026-1340?language=en_US&ref=labs.watchtowr.com


      OG¶«·½Ìü»ý¼«·ÀÓù³¢ÊÔÊÒ£¨ADLab£©


      ADLab³ÉÁ¢ÓÚ1999Äê £¬ÊÇÖйú°²È«ÐÐÒµ×îÔç³ÉÁ¢µÄ¹¥·À¼¼Êõ×êÑг¢ÊÔÊÒÖ®Ò» £¬Î¢ÈíMAPP´òËãÖ÷Ìâ³ÉÔ± £¬¡°ºÚȸ¹¥»÷¡±¸ÅÄîÊ×ÍÆÕß¡£½ØÖÁĿǰ £¬ADLabÒÑͨ¹ý CNVD/CNNVD/NVDB/CVEÀۼư䲼°²È«·ì϶7000Óà¸ö £¬³ÖÐøÎ¬³Ö¹ú¼ÊÍøÂ簲ȫÁìÓòÒ»Á÷Ë®×¼¡£³¢ÊÔÊÒ×êÑз½Ïòº­¸Ç»ù´¡°²È«×êÑС¢¡¢¡¢ÔËÓªÉÌ»ù´¡ÍøÂçÉèÊ©°²È«×êÑС¢¡¢¡¢Òƶ¯Öն˰²È«×êÑС¢¡¢¡¢Ôư²È«×êÑС¢¡¢¡¢ÐÅ´´°²È«×êÑС¢¡¢¡¢ÎïÁªÍø°²È«×êÑС¢¡¢¡¢³µÁªÍø°²È«×êÑС¢¡¢¡¢¹¤¿Ø°²È«×êÑС¢¡¢¡¢ÎÞÏß°²È«×êÑС¢¡¢¡¢Êý¾Ý°²È«×êÑС¢¡¢¡¢AI°²È«×êÑС¢¡¢¡¢µÍ¿Õ°²È«×êÑС¢¡¢¡¢¸ß¼¶Íþв×êÑС¢¡¢¡¢¹¥·Àϵͳ½¨Éè¡£×êÑгɾÍÀûÓÃÓÚ²úÆ·Ö÷Ìâ¼¼Êõ×êÑС¢¡¢¡¢¹ú¶ÈÖØµã¿Æ¼¼ÏîÄ¿¹¥¹Ø¡¢¡¢¡¢×¨Òµ°²È«·þÎñµÈ¡£


      adlab.jpg