ZeroHour

CVE-2025-4428

KEVlarge

Authenticated Code Injection RCE in Ivanti Endpoint Manager Mobile (EPMM) API

CISA: Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability

CVSS 3.1
8.8 high
EPSS
86%p100
Published
()
KEV added
AI analysis

CVE-2025-4428 is a code injection flaw (CWE-94) in the API component of Ivanti Endpoint Manager Mobile (EPMM) that lets an authenticated, low-privileged remote attacker execute arbitrary code by sending crafted API requests. Successful exploitation yields code execution on the MDM server itself (CVSS 8.8, High), which typically holds device inventory and administrative control over an organization's enrolled mobile fleet. Any organization running EPMM 12.5.0.0 or earlier is in scope. Exploitation is confirmed in the wild: CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2025-05-19, EPSS puts the 30-day exploitation probability at 86% (100th percentile), and public reporting ties limited attacks to the China-linked actor UNC5221, who reportedly began exploiting it alongside the companion API authentication bypass CVE-2025-4427 shortly after disclosure. CISA has also warned that threat actors exploiting these EPMM flaws deploy two malware strains; ransomware involvement has not been confirmed.

What to do: Upgrade every EPMM instance running 12.5.0.0 or earlier to the patched release per Ivanti's security advisory, prioritizing internet-facing servers, and note that federal agencies must satisfy the BOD 22-01 required action (patch, apply vendor mitigations, or discontinue use of the product). If patching is delayed, restrict internet exposure of the API and review EPMM logs and the advisory's indicators of compromise, since attackers have chained this flaw with the CVE-2025-4427 authentication bypass and deployed malware. Treat any unpatched, exposed EPMM instance as actively targeted until it is remediated.

Affected
Ivanti Endpoint Manager Mobile (EPMM)12.5.0.0 and prior (API component; affected platforms unspecified in the source data)
Estimated exposure
largetens of thousands of enterprise deployments (order of 10k-100k EPMM servers; many are internet-exposed) — EPMM (formerly MobileIron Core) is a per-organization enterprise MDM/UEM appliance that is frequently exposed to the internet for device check-in, so enterprise deployment patterns put the plausible installed base in the tens of thousands…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Remote Code Execution in API component in Ivanti Endpoint Manager Mobile 12.5.0.0 and prior on unspecified platforms allows authenticated attackers to execute arbitrary code via crafted API requests.

CISA Known Exploited Vulnerability
Affected
Ivanti Endpoint Manager Mobile (EPMM)
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
ivanti
Products
endpoint manager mobile
Weakness
CWE-94
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news