ZeroHour

CVE-2025-10985

large

Authenticated OS Command Injection RCE in Ivanti Endpoint Manager Mobile (EPMM)

CVSS 3.1
7.2 high
EPSS
21%p97
Published
()
Modified
AI analysis

CVE-2025-10985 is an operating system command injection flaw (CWE-78) in the admin panel of Ivanti Endpoint Manager Mobile (EPMM), an enterprise mobile device management product. An attacker who has already authenticated to the admin panel with administrator credentials can submit a crafted request that injects and runs arbitrary operating system commands on the EPMM server, achieving full remote code execution with high impact on confidentiality, integrity, and availability. Because administrator privileges are required, practical risk concentrates where an admin account is compromised, a privileged user is malicious, or the admin console is reachable from untrusted networks, and a successful attacker takes over the MDM server and, with it, the mobile fleet it manages. Organizations running EPMM on the 12.4, 12.5, or 12.6 branches prior to the fixed releases (12.4.0.4, 12.5.0.4, and 12.6.0.2) are affected. No public proof-of-concept or confirmed in-the-wild exploitation is known yet, but EPSS rates a 20.8% probability of exploitation within 30 days (97th percentile).

What to do: Upgrade EPMM to version 12.6.0.2, 12.5.0.4, or 12.4.0.4 to match your installed branch. Because exploitation requires authenticated administrator access, enforce MFA and strong credentials on the EPMM admin console, restrict admin-panel access to trusted networks or a VPN, and review admin accounts and application logs for signs of compromise. EPMM has been targeted by in-the-wild attacks before (the 2023 EPMM RCEs), so prioritize patching even though no exploitation of this CVE is currently reported.

Affected
Ivanti Endpoint Manager Mobile (EPMM)All 12.6.x releases prior to 12.6.0.2
Ivanti Endpoint Manager Mobile (EPMM)All 12.5.x releases prior to 12.5.0.4
Ivanti Endpoint Manager Mobile (EPMM)All 12.4.x releases prior to 12.4.0.4
Estimated exposure
largetens of thousands of EPMM deployments (~2,000-3,000 internet-exposed; millions of managed devices in aggregate) — Estimated from the former MobileIron/Ivanti enterprise MDM install base (on the order of 20,000+ enterprise customers reported before Ivanti's 2020 acquisition, typically one console or cluster per organization) and public internet scans…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

OS command injection in the admin panel of Ivanti EPMM before version 12.6.0.2, 12.5.0.4, and 12.4.0.4 allows a remote authenticated attacker with admin privileges to achieve remote code execution.

Vendors
ivanti
Products
endpoint manager mobile
Weakness
CWE-78
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.