Ivanti Patches 13 Vulnerabilities in Endpoint Manager Allowing Remote Code Execution
Ivanti has identified 13 vulnerabilities within its Endpoint Manager (EPM) software. This includes two high-severity vulnerabilities that could potentially allow remote code execution and privilege escalation. Ivanti advises users to apply interim…
Ivanti has identified 13 vulnerabilities within its Endpoint Manager (EPM) software. This includes two high-severity vulnerabilities that could potentially allow remote code execution and privilege escalation. Ivanti advises users to apply interim mitigations while patches are being developed.
Critical Vulnerabilities in Endpoint Manager
The vulnerabilities include CVE-2025-9713, a high-severity path traversal issue with a CVSS score of 8.8. This flaw permits unauthenticated remote attackers to execute arbitrary code if users interact with malicious files. The vulnerability exploits weak input validation during configuration imports, enabling potential adversaries to upload and execute malicious payloads on the EPM Core server.
Another significant flaw is CVE-2025-11622, an insecure deserialization vulnerability (CVSS 7.8), which allows local authenticated users to escalate privileges, gaining unauthorized access to sensitive system resources.
The remaining vulnerabilities are medium-severity SQL injection flaws (each CVSS 6.5), such as CVE-2025-11623 and CVE-2025-62392 through CVE-2025-62384. These vulnerabilities enable remote authenticated attackers to extract arbitrary data from the database without requiring user interaction beyond initial authentication.
Ivanti has identified 13 vulnerabilities within its Endpoint Manager (EPM) software.
For CVE-2025-11622, Ivanti recommends firewall whitelisting to block high-range TCP ports and restrict Core server access to local EPM administrators only. For the path traversal vulnerability CVE-2025-9713, it is advised that users avoid importing untrusted configuration files.
The SQL injection vulnerabilities can be mitigated by removing the Reporting database user, though this will disable analytics features. Ivanti's documentation provides more details on this trade-off. It is noted that using EPM 2024 SU3 SR1 or later versions offers enhanced security controls, reducing the risk of exploitation.
Ivanti EPM versions 2024 SU3 SR1 and earlier are affected, with the 2022 branch reaching end-of-life in October 2025. For the high-severity vulnerabilities, fixes are scheduled for EPM 2024 SU4, expected on Mon, Nov 12, 2025. The SQL injection vulnerabilities will be addressed in SU5 during Q1 2026.
Ivanti's open disclosure aims to enable proactive security measures in environments where endpoint managers are targeted by ransomware and advanced persistent threat (APT) groups. Organizations are encouraged to review their EPM setups and consult Ivanti’s Success Portal for tailored support.
Based on reporting by Cyber Security News.
