CVE-2025-10242: OS Command Injection
OS command injection in the admin panel of Ivanti EPMM before version 12.6.0.2, 12.5.0.4, and 12.4.0.4 allows a remote authenticated attacker with admin privileges to achieve remote code execution.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-10242?
CVE-2025-10242 is considered a critical vulnerability due to its potential for remote code execution.
How do I fix CVE-2025-10242?
To fix CVE-2025-10242, upgrade Ivanti EPMM to version 12.6.0.2 or higher, or 12.5.0.4 and higher.
Who is affected by CVE-2025-10242?
CVE-2025-10242 affects remote authenticated users with admin privileges on Ivanti EPMM versions prior to 12.6.0.2, 12.5.0.4, and 12.4.0.4.
What types of attacks can occur due to CVE-2025-10242?
CVE-2025-10242 allows attackers to execute arbitrary OS commands, potentially leading to complete system compromise.
Is there a way to mitigate risks associated with CVE-2025-10242 before applying the fix?
To mitigate risks from CVE-2025-10242, restrict access to the admin panel and monitor for suspicious activity while preparing to update.