¡¾¸´ÏÖ¡¿Ivanti Endpoint Manager MobileÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2026-1281ºÍCVE-2026-1340£©

Ðû²¼Ê±¼ä 2026-02-03

Ivanti Endpoint Manager Mobile(EPMM)£¬£¬£¬£¬£¬£¬Ô­ÃûMobileIron Core£¬£¬£¬£¬£¬£¬ÊÇÈ«ÇòÁìÏÈµÄÆóÒµ¼¶Í³Ò»¶ËµãÖÎÀí£¨UEM£©Æ½Ì¨¡£¡£¡£¡£


2026Äê1ÔÂ29ÈÕ£¬£¬£¬£¬£¬£¬IvantiÐû²¼¸üÐÂÐÞ¸´ÁËIvanti Endpoint Manager MobileÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2026-1281ºÍCVE-2026-1340£©£¬£¬£¬£¬£¬£¬CVSSÆÀ·Ö9.8·Ö£¨ÑÏÖØ£©¡£¡£¡£¡£ÎÊÌâ³öÔÚIvanti EPMMÔÚ´¦Öóͷ£Ìض¨URLʱ£¬£¬£¬£¬£¬£¬Apache»áͨ¹ýRewriteMap¹¦Ð§½«URLÖеIJÎÊýÖ±½Óת´ï¸øºó¶ËµÄBash¾ç±¾Ö´ÐС£¡£¡£¡£¹¥»÷ÕßÔڿɿصÄ×Ö·û´®´øÈëÁËËãÊõÀ©Õ¹ÉÏÏÂÎÄ£¬£¬£¬£¬£¬£¬µ¼Ö BashµÝ¹éÆÊÎö±äÁ¿Ãû²¢´¥·¢ÁË·´ÒýºÅÖеĶñÒâÏÂÁî¡£¡£¡£¡£


ƾ֤¹¥»÷ÃæÖÎÀíÆ½Ì¨ Censys µÄÊý¾Ý£¬£¬£¬£¬£¬£¬×èÖ¹ 2026 Äê2 Ô 2 ÈÕ£¬£¬£¬£¬£¬£¬»¥ÁªÍøÉϱ£´æ529¸öDZÔÚµÄÒ×Êܹ¥»÷Ivanti Endpoint Manager MobileʵÀý¡£¡£¡£¡£ÓÉÓÚ¿´·¨ÑéÖ¤Îó²îʹÓóÌÐòÒѾ­Ðû²¼£¬£¬£¬£¬£¬£¬²¢ÇÒ¸ÃÎó²îÒÑÔÚ»¥ÁªÍøÉÏÆÕ±éÈö²¥£¬£¬£¬£¬£¬£¬Òò´Ë¹ØÓÚʹÓÃIvanti Endpoint Manager MobileµÄ×éÖ¯¶øÑÔ£¬£¬£¬£¬£¬£¬¸ÃÎó²î×é³ÉÁËÖ±½ÓÇÒÑÏÖØµÄΣº¦¡£¡£¡£¡£


Îó²îÐÎò


ÔÚIvanti Endpoint Manager MobileϵͳÖУ¬£¬£¬£¬£¬£¬¸ÃϵͳµÄApache RewriteMapÉèÖÃÖÐÓÉÓû§ÌṩµÄÊäÈëת´ï¸øBash¾ç±¾Ö´ÐС£¡£¡£¡£½¹µãÇå¾²Îó²îÊÇÒ»¸öBashËãÊõÀ©Õ¹×¢ÈëÎó²î£¬£¬£¬£¬£¬£¬ÔÊÐíδ¾­Éí·ÝÑéÖ¤µÄ¹¥»÷ÕßÖ´ÐÐí§ÒâϵͳÏÂÁî¡£¡£¡£¡£ÏêϸÀ´Ëµ£º


    ? Ivanti Endpoint Manager MobileÖ±½Ó½«URLÖРsha256: ºóµÄÓû§ÊäÈëת´ï¸øBash¾ç±¾£¬£¬£¬£¬£¬£¬×÷ΪÂß¼­ÅжϵıäÁ¿£¬£¬£¬£¬£¬£¬È±·¦ÓÐÓõÄתÒå»ò¹ýÂË¡£¡£¡£¡£

    ? ¾ç±¾ÄÚ²¿µÄËãÊõ½ÏÁ¿Ä£¿£¿£¿£¿£¿ £¿£¿é(( )) ±£´æµÝ¹éÆÊÎöÌØÕ÷£¬£¬£¬£¬£¬£¬¹¥»÷ÕßʹÓñäÁ¿¼äµÄǶÌ×ÒýÓÃʵÏÖÔ¶³Ì´úÂëÖ´ÐС£¡£¡£¡£


Ivanti¹Ù·½ÐÎòΪ£ºA code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.


Ó°Ïì¹æÄ£


Ivanti Endpoint Manager Mobile < =12.5.0.0

Ivanti Endpoint Manager Mobile < =12.5.1.0

Ivanti Endpoint Manager Mobile < =12.6.0.0

Ivanti Endpoint Manager Mobile < =12.6.1.0

Ivanti Endpoint Manager Mobile < =12.7.0.0


Îó²îÔ­Àí


Îó²îÔ´ÓÚApache HTTPdÉèÖÃÁËRewriteMap£¨mapAppStoreURL ºÍ mapAftStoreURL£©£¬£¬£¬£¬£¬£¬Ö±½Ó½«Î´¾­ÓÉÂ˵ÄURL²ÎÊýת´ï¸øµ×²ãµÄBash¾ç±¾£¬£¬£¬£¬£¬£¬´¥·¢Â·¾¶Îª /mifs/c/appstore/fob/3/...£¬£¬£¬£¬£¬£¬¸Ã·¾¶²»ÐèÒªÈκÎÉí·ÝÑéÖ¤£¬£¬£¬£¬£¬£¬´úÂëÈçÏ£º


    RewriteRule ^/mifs/c/appstore/fob/3/([0-9]+)/sha256:(.*)/(.*)(.ipa)$ ${mapAppStoreURL:$2_$1_$3_$4_%{HTTP_HOST}_%{ENV:SCRIPT_URL}} [T=application/octet-stream,UnsafePrefixStat]


    ¹¥»÷Õß¿ÉÒÔͨ¹ý¿ØÖÆsha256:kid=... ºóÃæµÄ×Ö·û´®£¬£¬£¬£¬£¬£¬½«¶ñÒâÏÂÁî×¢Èëµ½Bash¾ç±¾´¦Öóͷ£Á÷³ÌÖУ¬£¬£¬£¬£¬£¬¾ç±¾Â·¾¶£º/mi/bin/map-appstore-url£¬£¬£¬£¬£¬£¬´úÂëÈçÏ£º


    ͼƬ1.png


    Îó²î¸´ÏÖ


    ÔÚyakitÖз¢ËÍPOC£¬£¬£¬£¬£¬£¬Ö´ÐÐping dnslogÏÂÁî¡£¡£¡£¡£


    ͼƬ2.png


    ÎüÊÕµ½dnslogÑéÖ¤£¬£¬£¬£¬£¬£¬¼´ping dnslogÏÂÁîÖ´ÐÐÀֳɡ£¡£¡£¡£


    ͼƬ3.png


    Çå¾²½¨Òé


      £¨1£©Á¬Ã¦Éý¼¶

      Ivanti Endpoint Manager Mobile¹Ù·½ÒÑÐû²¼Ç徲ͨ¸æ£¬£¬£¬£¬£¬£¬Çë°´Ö¸µ¼¾ÙÐÐÐÞ¸´¡£¡£¡£¡£


      £¨2£©ÔÝʱ»º½â²½·¥

      Ó¦ÓÃÔÝʱRPM²¹¶¡£¡£¡£¡£º

      ? ÊÊÓÃÓÚ12.5.0.x¡¢12.6.0.x¡¢12.7.0.x°æ±¾£ºinstall rpm url 

      https://username:password@support.mobileiron.com/mi/vsp/AB1771634/ivanti-security-update-1761642-1.0.0S-5.noarch.rpm

      ÊÊÓÃÓÚ12.5.1.0ºÍ12.6.1.0°æ±¾£ºinstall rpm url

      https://username:password@support.mobileiron.com/mi/vsp/AB1771634/ivanti-security-update-1761642-1.0.0L-5.noarch.rpm


      ²Î¿¼Á´½Ó£º


      [1]https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Endpoint-Manager-Mobile-EPMM-CVE-2026-1281-CVE-2026-1340?language=en_US&ref=labs.watchtowr.com


      Z6×ðÁú¿­Ê±Æð¾¢·ÀÓùʵÑéÊÒ£¨ADLab£©


      ADLab½¨ÉèÓÚ1999Ä꣬£¬£¬£¬£¬£¬ÊÇÖйúÇå¾²ÐÐÒµ×îÔ罨ÉèµÄ¹¥·ÀÊÖÒÕÑо¿ÊµÑéÊÒÖ®Ò»£¬£¬£¬£¬£¬£¬Î¢ÈíMAPPÍýÏë½¹µã³ÉÔ±£¬£¬£¬£¬£¬£¬¡°ºÚȸ¹¥»÷¡±¿´·¨Ê×ÍÆÕß¡£¡£¡£¡£×èÖ¹ÏÖÔÚ£¬£¬£¬£¬£¬£¬ADLabÒÑͨ¹ý CNVD/CNNVD/NVDB/CVEÀÛ¼ÆÐû²¼Çå¾²Îó²î7000Óà¸ö£¬£¬£¬£¬£¬£¬Ò»Á¬¼á³Ö¹ú¼ÊÍøÂçÇå¾²ÁìÓòÒ»Á÷Ë®×¼¡£¡£¡£¡£ÊµÑéÊÒÑо¿Æ«Ïòº­¸Ç»ù´¡Çå¾²Ñо¿¡¢ÔËÓªÉÌ»ù´¡ÍøÂçÉèÊ©Çå¾²Ñо¿¡¢Òƶ¯ÖÕ¶ËÇå¾²Ñо¿¡¢ÔÆÇå¾²Ñо¿¡¢ÐÅ´´Çå¾²Ñо¿¡¢ÎïÁªÍøÇå¾²Ñо¿¡¢³µÁªÍøÇå¾²Ñо¿¡¢¹¤¿ØÇå¾²Ñо¿¡¢ÎÞÏßÇå¾²Ñо¿¡¢Êý¾ÝÇå¾²Ñо¿¡¢AIÇå¾²Ñо¿¡¢µÍ¿ÕÇå¾²Ñо¿¡¢¸ß¼¶ÍþвÑо¿¡¢¹¥·Àϵͳ½¨Éè¡£¡£¡£¡£Ñо¿Ð§¹ûÓ¦ÓÃÓÚ²úÆ·½¹µãÊÖÒÕÑо¿¡¢¹ú¼ÒÖØµã¿Æ¼¼ÏîÄ¿¹¥¹Ø¡¢×¨ÒµÇ徲ЧÀ͵È¡£¡£¡£¡£


      adlab.jpg