CVE-2025-13659: High severity Ivanti Endpoint Manager vulnerability
Improper control of dynamically managed code resources in Ivanti Endpoint Manager prior to version 2024 SU4 SR1 allows a remote, unauthenticated attacker to write arbitrary files on the server, potentially leading to remote code execution. User interaction is required.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-13659?
CVE-2025-13659 has a critical severity rating due to the potential for remote code execution by unauthenticated attackers.
How do I fix CVE-2025-13659?
To fix CVE-2025-13659, upgrade Ivanti Endpoint Manager to version 2024 SU4 SR1 or later.
What impact does CVE-2025-13659 have on my system?
CVE-2025-13659 allows attackers to write arbitrary files on the server, which can lead to serious security breaches.
Is user interaction required for exploiting CVE-2025-13659?
Yes, user interaction is required for exploiting CVE-2025-13659, making it slightly less straightforward for attackers.
Which software versions are affected by CVE-2025-13659?
Ivanti Endpoint Manager versions prior to 2024 SU4 SR1 are affected by CVE-2025-13659.