• News/
  • https://www.bleepingcomputer.com/news/security/ivanti-fixes-epmm-zero-days-chained-in-code-execution-attacks/

Ivanti fixes EPMM zero-days chained in code execution attacks

BleepingComputer
·
Sergiu Gatlan
·
Published May 13, 2025
·
Updated

Ivanti warned customers today to patch their Ivanti Endpoint Manager Mobile (EPMM) software against two security vulnerabilities chained in attacks to gain remote code execution. "Ivanti has released updates for Endpoint Manager Mobile (EPMM) which addresses one medium and one high severity vulnerability," the company said. "When chained together, successful exploitation could lead to unauthenticated remote code execution. We are aware of a very limited number of customers whose solution has been exploited at the time of disclosure." The first security flaw (CVE-2025-4427) is an authentication bypass in EPMM's API component, allowing attackers to access protected resources on vulnerable devices. The second (tracked as CVE-2025-4428) is a remote code execution vulnerability that allows threat actors to execute arbitrary code on targeted systems via maliciously crafted API requests. Ivanti says customers can mitigate the two zero-day flaws by installing Ivanti Endpoint Manager Mobile 11.12.0.5, 12.3.0.2, 12.4.0.2, or 12.5.0.1. The company added that, while it's still investigating these attacks and can't provide indicators of compromise, customers should reach out to the support team for further guidance. While Ivanti said the two vulnerabilities are "associated" with two open-source libraries used by EPMM, it didn't share their names in the advisory. A spokesperson directed BleepingComputer to today's advisory for further information. "The issue only affects the on-prem EPMM ...

Read full article

Affected Software

7 affected components
Ivanti Endpoint Manager Mobile=11.12.0.5
Ivanti Endpoint Manager Mobile=12.3.0.2
Ivanti Endpoint Manager Mobile=12.4.0.2
Ivanti Endpoint Manager Mobile=12.5.0.1
Ivanti Neurons for ITSM
Ivanti Cloud Services Appliance
Ivanti Endpoint Manager Mobile=11
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What security vulnerabilities were addressed in the Ivanti article?

Ivanti addressed two zero-day vulnerabilities in their Endpoint Manager Mobile (EPMM) software that could lead to remote code execution.

2

Which versions of Ivanti software are affected by the vulnerabilities?

The affected versions include Ivanti Endpoint Manager Mobile 11.12.0.5, 12.3.0.2, 12.4.0.2, and 12.5.0.1.

3

What is the main recommendation for Ivanti customers in light of these vulnerabilities?

Ivanti customers are advised to promptly update their Endpoint Manager Mobile software to mitigate the security risks.

4

What types of attacks are possible due to the vulnerabilities?

The vulnerabilities could be exploited in chained attacks to achieve remote code execution on affected systems.

5

Who is the vendor responsible for the affected security products?

The vendor responsible for the affected security products is Ivanti.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203