CVE-2025-10243
largeAuthenticated OS Command Injection Leading to Admin RCE in Ivanti EPMM
CVE-2025-10243 is an OS command injection flaw (CWE-78) in the admin panel of Ivanti Endpoint Manager Mobile (EPMM), Ivanti's enterprise mobile device management platform. A remote attacker who is already authenticated with administrator-level privileges can submit crafted input that is passed to the underlying operating system, triggering arbitrary command execution. Successful exploitation yields full RCE on the EPMM server, with high impact to confidentiality, integrity, and availability (CVSS 3.1 base 7.2, PR:H/AV:N), potentially giving the attacker access to data about the mobile devices and users managed by the platform. Affected organizations are those running EPMM versions prior to 12.6.0.2, 12.5.0.4, or 12.4.0.4 on their respective release branches; because exploitation requires admin credentials, exposure is limited to attackers who hold or have compromised an EPMM administrator account. No public proof-of-concept, confirmed in-the-wild exploitation, or KEV listing is known, but an EPSS of 20.8% (97th percentile) indicates an elevated probability of exploitation within the next 30 days.
What to do: Upgrade EPMM to version 12.6.0.2, 12.5.0.4, or 12.4.0.4 depending on the branch in use. Until patched, restrict access to the EPMM admin panel to trusted management networks or VPN, minimize the number of admin accounts, and rotate/audit admin credentials for signs of compromise. Since this is a command injection reachable from the admin panel, review recent administrator activity and server logs for unexplained command execution or process launches.
| Ivanti Endpoint Manager Mobile (EPMM) | All versions before 12.4.0.4, 12.5.0.4, and 12.6.0.2 on their respective supported release branches (fixed in 12.4.0.4, 12.5.0.4, and 12.6.0.2) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
OS command injection in the admin panel of Ivanti EPMM before version 12.6.0.2, 12.5.0.4, and 12.4.0.4 allows a remote authenticated attacker with admin privileges to achieve remote code execution.
- Vendors
- ivanti
- Products
- endpoint manager mobile
- Weakness
- CWE-78
- Vector
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.