Ivanti warned customers today to patch their Ivanti Endpoint Manager Mobile (EPMM) software against two security vulnerabilities chained in attacks to gain remote code execution. "Ivanti has released updates for Endpoint Manager Mobile (EPMM) which addresses one medium and one high severity vulnerability," the company said. "When chained together, successful exploitation could lead to unauthenticated remote code execution. We are aware of a very limited number of customers whose solution has been exploited at the time of disclosure." The first security flaw (CVE-2025-4427) is an authentication bypass in EPMM's API component, allowing attackers to access protected resources on vulnerable devices. The second (tracked as CVE-2025-4428) is a remote code execution vulnerability that allows threat actors to execute arbitrary code on targeted systems via maliciously crafted API requests. Ivanti says customers can mitigate the two zero-day flaws by installing Ivanti Endpoint Manager Mobile 11.12.0.5, 12.3.0.2, 12.4.0.2, or 12.5.0.1. The company added that, while it's still investigating these attacks and can't provide indicators of compromise, customers should reach out to the support team for further guidance. While Ivanti said the two vulnerabilities are "associated" with two open-source libraries used by EPMM, it didn't share their names in the advisory. A spokesperson directed BleepingComputer to today's advisory for further information. "The issue only affects the on-prem EPMM ...
Ivanti fixes EPMM zero-days chained in code execution attacks
BleepingComputer
·Sergiu Gatlan
·Published May 13, 2025
·Updated
Affected Software
7 affected components
Ivanti Endpoint Manager Mobile=11.12.0.5
Ivanti Endpoint Manager Mobile=12.3.0.2
Ivanti Endpoint Manager Mobile=12.4.0.2
Ivanti Endpoint Manager Mobile=12.5.0.1
Ivanti Neurons for ITSM
Ivanti Cloud Services Appliance
Ivanti Endpoint Manager Mobile=11
Frequently Asked Questions
1
What security vulnerabilities were addressed in the Ivanti article?
Ivanti addressed two zero-day vulnerabilities in their Endpoint Manager Mobile (EPMM) software that could lead to remote code execution.
2
Which versions of Ivanti software are affected by the vulnerabilities?
The affected versions include Ivanti Endpoint Manager Mobile 11.12.0.5, 12.3.0.2, 12.4.0.2, and 12.5.0.1.
3
What is the main recommendation for Ivanti customers in light of these vulnerabilities?
Ivanti customers are advised to promptly update their Endpoint Manager Mobile software to mitigate the security risks.
4
What types of attacks are possible due to the vulnerabilities?
The vulnerabilities could be exploited in chained attacks to achieve remote code execution on affected systems.
5
Who is the vendor responsible for the affected security products?
The vendor responsible for the affected security products is Ivanti.