CVE-2025-9712: Malicious File Upload
Published Sep 9, 2025
·Updated
Insufficient filename validation in Ivanti Endpoint Manager before 2024 SU3 SR1 and 2022 SU8 SR2 allows a remote unauthenticated attacker to achieve remote code execution. User interaction is required.
Affected Software
15 affected components
Ivanti Endpoint Manager<2024 SU3 SR1, <2022 SU8 SR2
Ivanti Endpoint Manager<2022
Ivanti Endpoint Manager=2022
Ivanti Endpoint Manager=2022-su1
Ivanti Endpoint Manager=2022-su2
Ivanti Endpoint Manager=2022-su3
Ivanti Endpoint Manager=2022-su4
Ivanti Endpoint Manager=2022-su5
Ivanti Endpoint Manager=2022-su6
Ivanti Endpoint Manager=2022-su7
Ivanti Endpoint Manager=2022-su8
Ivanti Endpoint Manager=2022-su8_security_release_1
Ivanti Endpoint Manager=2024
Ivanti Endpoint Manager=2024-su1
Ivanti Endpoint Manager=2024-su2
Event History
Sep 9, 2025
CVE Published
via MITRE·03:09 PM
Data Sourced
via MITRE·03:09 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
Feb 11, 58000
Event
via FIRST·03:25 AM
Frequently Asked Questions
1
What is the severity of CVE-2025-9712?
CVE-2025-9712 has a high severity rating due to its potential for remote code execution by unauthenticated attackers.
2
How do I fix CVE-2025-9712?
To mitigate CVE-2025-9712, you should update to Ivanti Endpoint Manager version 2024 SU3 Security Update 1 or later, and 2022 SU8 Security Update 2 or later.
3
What kind of attack can CVE-2025-9712 enable?
CVE-2025-9712 can enable a remote unauthenticated attacker to execute arbitrary code on affected systems.
4
What versions of Ivanti Endpoint Manager are affected by CVE-2025-9712?
CVE-2025-9712 affects Ivanti Endpoint Manager versions prior to 2024 SU3 and 2022 SU8.
5
Is user interaction required to exploit CVE-2025-9712?
Yes, CVE-2025-9712 requires user interaction for successful exploitation.