ZDI-CAN-28116: ZDI-25-1052: Ivanti Endpoint Manager CAB File Parsing Directory Traversal Remote Code Execution Vulnerability
Published Dec 10, 2025
·Updated
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ivanti Endpoint Manager. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.1. The following CVEs are assigned: CVE-2025-13661.
Affected Software
1 affected component
Ivanti Endpoint Manager
Event History
Dec 10, 2025
Advisory Published
via ZDI·06:00 AM
Data Sourced
via ZDI·06:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-CAN-28116?
The severity of ZDI-CAN-28116 is rated at 7.1 on the CVSS scale.
2
How do I fix ZDI-CAN-28116?
To fix ZDI-CAN-28116, apply the latest security patches and updates provided by Ivanti for Endpoint Manager.
3
What type of attack does ZDI-CAN-28116 allow?
ZDI-CAN-28116 allows remote attackers to execute arbitrary code on affected installations.
4
Is authentication required to exploit ZDI-CAN-28116?
Yes, authentication is required to exploit the ZDI-CAN-28116 vulnerability.
5
Which software is affected by ZDI-CAN-28116?
The affected software for ZDI-CAN-28116 is Ivanti Endpoint Manager.