Ivanti Patches 13 Endpoint Manager Flaws Allowing Remote Code Execution
## Cybersecurity: Ivanti Endpoint Manager Vulnerabilities
Cybersecurity: Ivanti Endpoint Manager Vulnerabilities
Ivanti has reported 13 vulnerabilities in Ivanti Endpoint Manager (EPM), including two high-severity issues that could lead to privilege escalation and remote code execution, and eleven medium-severity SQL injection flaws.
Although there is no evidence of active exploitation, Ivanti advises customers to upgrade to the latest supported release and follow recommended mitigations as patches are being developed.
Ivanti has announced that EPM 2022 will reach end-of-life in October 2025. Ivanti EPM 2024 includes significant security enhancements that reduce risk.
For supported versions, fixes will be released in two phases: patches for insecure deserialization and path traversal vulnerabilities will be available in Ivanti EPM 2024 SU4, targeted for November 12, 2025. The SQL injection issues are scheduled for resolution in EPM 2024 SU5 in Q1 2026.
Administrators should implement workarounds to minimize exposure in the interim.
CVE-2025-11622 : Insecure deserialization allows a local authenticated attacker to escalate privileges (CVSS 7.8, CWE-502). CVE-2025-9713 : Path traversal enables remote code execution by an unauthenticated attacker, requiring user interaction (CVSS 8.8, CWE-22).
Ivanti has announced that EPM 2022 will reach end-of-life in October 2025.
The remaining eleven CVEs are SQL injection vulnerabilities that permit remote authenticated users to access arbitrary database data (CVSS 6.5, CWE-89).
For CVE-2025-11622 , customers on EPM 2024 SU3 SR1 have reduced risk. Those not upgraded should whitelist and restrict access via a reliable firewall to block remote access to arbitrary high-range TCP ports and limit EPM Core server access to local administrators only. For CVE-2025-9713 , avoid importing untrusted configuration files into the EPM Core server; if necessary, review file contents carefully, acknowledging inherent risk. For SQL injection issues, removing the Reporting database user can eliminate exposure, but this will disable reporting functionality as a read-only reporting user is required to run any EPM report.
Vulnerabilities affect Ivanti EPM 2024 SU3 SR1 and prior, with patches pending as noted, and Ivanti EPM 2022 SU8 SR2 and prior, which are end-of-life and should be upgraded to EPM 2024.
Organizations should review administrative access, strengthen firewall rules, and avoid untrusted imports to reduce the attack surface until updates are available.
CVE Description CVSS (Severity) CWE
CVE-2025-11622 Insecure deserialization allows local privilege escalation 7.8 (High) CWE-502
CVE-2025-9713 Path traversal allows RCE; UI required; unauthenticated 8.8 (High) CWE-22
CVE-2025-11623 SQL injection allows data read (authenticated) 6.5 (Medium) CWE-89
Upgrade planning should prioritize transitioning to Ivanti EPM 2024 and preparing for SU4 and SU5 rollout, while applying strict least-privilege, network segmentation, and input validation practices to mitigate risk during the interim.
Based on reporting by GBHackers.
