By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
World of SoftwareWorld of SoftwareWorld of Software
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Search
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
Reading: Ivanti Patches EPMM Vulnerabilities Exploited for Remote Code Execution in Limited Attacks
Share
Sign In
Notification Show More
Font ResizerAa
World of SoftwareWorld of Software
Font ResizerAa
  • Software
  • Mobile
  • Computing
  • Gadget
  • Gaming
  • Videos
Search
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Have an existing account? Sign In
Follow US
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
World of Software > Computing > Ivanti Patches EPMM Vulnerabilities Exploited for Remote Code Execution in Limited Attacks
Computing

Ivanti Patches EPMM Vulnerabilities Exploited for Remote Code Execution in Limited Attacks

News Room
Last updated: 2025/05/14 at 1:51 AM
News Room Published 14 May 2025
Share
SHARE

May 14, 2025Ravie LakshmananVulnerability / Endpoint Security

Ivanti has released security updates to address two security flaws in Endpoint Manager Mobile (EPMM) software that have been chained in attacks to gain remote code execution.

The vulnerabilities in question are listed below –

  • CVE-2025-4427 (CVSS score: 5.3) – An authentication bypass in Ivanti Endpoint Manager Mobile allowing attackers to access protected resources without proper credentials
  • CVE-2025-4428 (CVSS score: 7.2) – A remote code execution vulnerability in Ivanti Endpoint Manager Mobile allowing attackers to execute arbitrary code on the target system
Cybersecurity

The flaws impact the following versions of the product –

  • 11.12.0.4 and prior (Fixed in 11.12.0.5)
  • 12.3.0.1 and prior (Fixed in 12.3.0.2)
  • 12.4.0.1 and prior (Fixed in 12.4.0.2)
  • 12.5.0.0 and prior (Fixed in 12.5.0.1)

Ivanti, which credited CERT-EU for reporting the issues, said it’s “aware of a very limited number of customers who have been exploited at the time of disclosure” and that the vulnerabilities are “associated with two open-source libraries integrated into EPMM.”

The company, however, did not disclose the names of the impacted libraries. It’s also not known what other software applications relying on the two libraries could be affected. Furthermore, the company said it’s still investigating the cases, and that it does not have reliable indicators of compromise associated with the malicious activity.

“The risk to customers is significantly reduced if they already filter access to the API using either the built-in Portal ACLs functionality or an external web application firewall,” Ivanti noted.

“The issue only affects the on-prem EPMM product. It is not present in Ivanti Neurons for MDM, Ivanti’s cloud-based unified endpoint management solution, Ivanti Sentry, or any other Ivanti products.”

Cybersecurity

Separately, Ivanti has also shipped patches to contain an authentication bypass flaw in on-premise versions of Neurons for ITSM (CVE-2025-22462, CVSS score: 9.8) that could allow a remote unauthenticated attacker to gain administrative access to the system. There is no evidence that the security defect has been exploited in the wild.

With zero-days in Ivanti appliances becoming a lightning rod for threat actors in recent years, it’s imperative that users move quickly to update their instances to the latest versions for optimal protection.

Found this article interesting? Follow us on Twitter  and LinkedIn to read more exclusive content we post.

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Twitter Email Print
Share
What do you think?
Love0
Sad0
Happy0
Sleepy0
Angry0
Dead0
Wink0
Previous Article Walmart Brings Back 'Basket Fee' for Some Orders: What To Know
Next Article What we know about Diddy’s rumored girlfriend Dana Tran & the child they share
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Stay Connected

248.1k Like
69.1k Follow
134k Pin
54.3k Follow

Latest News

PayPal starts rolling out direct iPhone NFC payments in Europe – 9to5Mac
News
Today's NYT Mini Crossword Answers for May 14 – CNET
News
Audio Technica ATH-CC500BT2
Gadget
Food grown with fewer chemicals? A Brazilian scientist wins $500,000 for showing the way
News

You Might also Like

Computing

13 Best Voice Over Software for High-Quality Audio Production

34 Min Read
Computing

7 Ways to Grow Client Value and Monthly Revenue

17 Min Read
Computing

Rustls Server-Side Performance Looking Very Good Compared To OpenSSL

1 Min Read
Computing

CATL seeks to manufacture batteries in the US pending Trump’s approval · TechNode

1 Min Read
//

World of Software is your one-stop website for the latest tech news and updates, follow us now to get the news that matters to you.

Quick Link

  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact

Topics

  • Computing
  • Software
  • Press Release
  • Trending

Sign Up for Our Newsletter

Subscribe to our newsletter to get our newest articles instantly!

World of SoftwareWorld of Software
Follow US
Copyright © All Rights Reserved. World of Software.
Welcome Back!

Sign in to your account

Lost your password?