CVE-2025-10242
largeAuthenticated OS Command Injection RCE in Ivanti Endpoint Manager Mobile (EPMM)
CVE-2025-10242 is an OS command injection flaw (CWE-78) in the admin panel of Ivanti Endpoint Manager Mobile (EPMM), the enterprise mobile device management platform formerly known as MobileIron Core. An attacker who has obtained valid administrator credentials can send crafted input through the admin panel over the network, causing arbitrary operating system commands to run on the server. Successful exploitation yields full remote code execution with high impact to confidentiality, integrity, and availability on the EPMM appliance, which typically sits at the center of an organization's mobile fleet management. Organizations running EPMM in the 12.4, 12.5, or 12.6 release branches are affected until they apply the patched releases. No public proof-of-concept, in-the-wild exploitation, or KEV listing is currently known, but the 20.8% EPSS score (97th percentile) indicates an elevated probability of exploitation within the next 30 days.
What to do: Upgrade EPMM to 12.6.0.2, 12.5.0.4, or 12.4.0.4 (or later) depending on your release branch. Until patched, restrict access to the admin panel to trusted networks and review admin accounts for unauthorized or compromised credentials, since exploitation requires admin privileges. Because the EPSS score signals elevated near-term exploitation risk, prioritize patching internet-exposed EPMM servers first and monitor admin-panel logs for anomalous commands.
| Ivanti Endpoint Manager Mobile (EPMM) | All versions before 12.6.0.2 (12.6 branch), before 12.5.0.4 (12.5 branch), and before 12.4.0.4 (12.4 branch) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
OS command injection in the admin panel of Ivanti EPMM before version 12.6.0.2, 12.5.0.4, and 12.4.0.4 allows a remote authenticated attacker with admin privileges to achieve remote code execution.
- Vendors
- ivanti
- Products
- endpoint manager mobile
- Weakness
- CWE-78
- Vector
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.