Ivanti Endpoint Manager Remote Code Execution Vulnerability

Vulnerability

A remote code execution vulnerability has been identified in Ivanti Endpoint Manager (EPM) versions 2022 SU8 Security Update 1 and prior, as well as in EPM 2024 SU3 and prior. This vulnerability arises from insufficient filename validation, allowing remote unauthenticated attackers to execute code. Exploitation of this issue requires user interaction.

Impact

Exploitation of this vulnerability allows for remote code execution on the affected system.

Remediation

Users can upgrade to Ivanti Endpoint Manager 2024 SU3 Security Release 1 or Ivanti Endpoint Manager 2022 SU8 Security Release 2. These versions are available for download in the Ivanti License System (ILS).

Added: Sep 9, 2025, 4:17 PM
Updated: Sep 9, 2025, 10:25 PM

Vulnerability Rating

Custom Algorithm
spread
4.5
impact
7.5
exploitability
6.0
remediation
7.7
relevance
0.5
threat
0.1
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.