ZeroHour

CVE-2025-10243

large

Authenticated OS Command Injection Leading to Admin RCE in Ivanti EPMM

CVSS 3.1
7.2 high
EPSS
21%p97
Published
()
Modified
AI analysis

CVE-2025-10243 is an OS command injection flaw (CWE-78) in the admin panel of Ivanti Endpoint Manager Mobile (EPMM), Ivanti's enterprise mobile device management platform. A remote attacker who is already authenticated with administrator-level privileges can submit crafted input that is passed to the underlying operating system, triggering arbitrary command execution. Successful exploitation yields full RCE on the EPMM server, with high impact to confidentiality, integrity, and availability (CVSS 3.1 base 7.2, PR:H/AV:N), potentially giving the attacker access to data about the mobile devices and users managed by the platform. Affected organizations are those running EPMM versions prior to 12.6.0.2, 12.5.0.4, or 12.4.0.4 on their respective release branches; because exploitation requires admin credentials, exposure is limited to attackers who hold or have compromised an EPMM administrator account. No public proof-of-concept, confirmed in-the-wild exploitation, or KEV listing is known, but an EPSS of 20.8% (97th percentile) indicates an elevated probability of exploitation within the next 30 days.

What to do: Upgrade EPMM to version 12.6.0.2, 12.5.0.4, or 12.4.0.4 depending on the branch in use. Until patched, restrict access to the EPMM admin panel to trusted management networks or VPN, minimize the number of admin accounts, and rotate/audit admin credentials for signs of compromise. Since this is a command injection reachable from the admin panel, review recent administrator activity and server logs for unexplained command execution or process launches.

Affected
Ivanti Endpoint Manager Mobile (EPMM)All versions before 12.4.0.4, 12.5.0.4, and 12.6.0.2 on their respective supported release branches (fixed in 12.4.0.4, 12.5.0.4, and 12.6.0.2)
Estimated exposure
largeon the order of hundreds of thousands of managed devices/users across several thousand enterprise EPMM deployments (estimate) — EPMM (formerly MobileIron Core) is enterprise MDM deployed by thousands of organizations, and public internet scans have historically shown a few thousand exposed instances, each typically managing large corporate mobile fleets, implying a…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

OS command injection in the admin panel of Ivanti EPMM before version 12.6.0.2, 12.5.0.4, and 12.4.0.4 allows a remote authenticated attacker with admin privileges to achieve remote code execution.

Vendors
ivanti
Products
endpoint manager mobile
Weakness
CWE-78
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.