On 24 July 2023 Norwegian authorities disclosed that twelve government ministries had been affected by exploitation of CVE-2023-35078, a zero-day in Ivanti Endpoint Manager Mobile. The flaw is an authentication bypass permitting unauthenticated remote API access, carrying a CVSS score of 10.0, and allows retrieval of user data such as names and phone numbers and modification of the server.
Reporting placed exploitation from at least April 2023, and a second zero-day was subsequently reported used in the same activity. The affected ministries shared an ICT platform operated by the government services agency; the Office of the Prime Minister, the Ministry of Defence, the Ministry of Justice and Public Security and the Ministry of Foreign Affairs were not on it.
The Exclusion List Is The Finding
We have argued at 26-0704 that a shared platform concentrates risk across everyone on it, and at 23-0818b that isolation is the control which quietly does the work. Those arguments are usually made from the damage.
Here the counterfactual is legible. Four ministries were judged sensitive enough to keep separate, and those four are exactly the four that were not affected. The judgement was made years earlier, for reasons of classification rather than resilience, and it functioned as a security control anyway.
Three Months Before Anyone Knew
Exploitation from April and disclosure in July means a quarter of a year in which a maximum-severity flaw was being used against a government and nobody outside the operation knew it existed.
We have recorded the same interval at 22-0527, where a flaw was reported to a vendor six weeks before it became public, and at 23-1010b. What distinguishes a zero-day is not the technical quality but the silence, and the silence is what we keep finding was the expensive part.
The Product Manages The Phones
Endpoint management software exists to control an organisation’s mobile devices — to enrol them, configure them and push policy. It therefore holds a directory of who works there and what they carry, and by design has authority over those devices.
We have recorded the same profile at 22-0118, where a self-service password tool was the entry, and at 23-0413. The systems that administer other systems are the highest-value targets in any estate, and they are consistently the least examined, because they are infrastructure rather than applications.
Compiled from contemporaneous reporting and vendor advisories, listed below. The observation that those four were excluded for classification reasons rather than resilience planning is this desk’s reading of the reported arrangement and is presented as such. No actor is named: reporting described an advanced persistent threat without public attribution to a state. No indicators are reproduced. Graded high. Corrections: corrections@forensicpost.com.