CVE-2025-13661: Path Traversal
Published Dec 9, 2025
·Updated
Path traversal in Ivanti Endpoint Manager prior to version 2024 SU4 SR1 allows a remote authenticated attacker to write arbitrary files outside of the intended directory. User interaction is required.
Affected Software
8 affected components
Ivanti Endpoint Manager<2024 SU4 SR1
Ivanti Endpoint Manager<2024
Ivanti Endpoint Manager=2024
Ivanti Endpoint Manager=2024-su1
Ivanti Endpoint Manager=2024-su2
Ivanti Endpoint Manager=2024-su3
Ivanti Endpoint Manager=2024-su3_security_release_1
Ivanti Endpoint Manager=2024-su4
Event History
Dec 9, 2025
CVE Published
via MITRE·04:01 PM
Data Sourced
via MITRE·04:01 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:17 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-13661?
CVE-2025-13661 has a severity rating of high due to the potential for remote authenticated attackers to write arbitrary files.
2
How do I fix CVE-2025-13661?
To fix CVE-2025-13661, upgrade to Ivanti Endpoint Manager version 2024 SU4 SR1 or later.
3
Who is affected by CVE-2025-13661?
CVE-2025-13661 affects users of Ivanti Endpoint Manager versions prior to 2024 SU4 SR1.
4
What type of vulnerability is CVE-2025-13661?
CVE-2025-13661 is a path traversal vulnerability that allows unauthorized file writing.
5
What conditions are required to exploit CVE-2025-13661?
Exploitation of CVE-2025-13661 requires remote authentication and user interaction.