ZeroHour

CVE-2025-9712

large

Unauthenticated RCE via Filename Validation Flaw in Ivanti Endpoint Manager

CVSS 3.1
8.8 high
EPSS
21%p97
Published
()
Modified
AI analysis

CVE-2025-9712 is a remote code execution vulnerability in Ivanti Endpoint Manager caused by insufficient filename validation (CWE-434), meaning files with crafted or unsafe names are not properly checked by the product. A remote, unauthenticated attacker can trigger the flaw over the network, but exploiting it requires some user interaction (CVSS:3.1 AV:N/AC:L/PR:N/UI:R, score 8.8 High). Successful exploitation gives the attacker code execution with high impact on confidentiality, integrity, and availability on the affected Endpoint Manager installation. Organizations running Ivanti Endpoint Manager 2024 before SU3 SR1 or the 2022 line before SU8 SR2 are affected. No public proof-of-concept or confirmed in-the-wild exploitation is known, but EPSS assigns a 20.5% probability of exploitation within 30 days (97th percentile), indicating elevated near-term risk.

What to do: Upgrade Ivanti Endpoint Manager 2024 to SU3 SR1 (or later) and Endpoint Manager 2022 to SU8 SR2 (or later). Restrict network access to the Endpoint Manager server from untrusted networks and check whether any EPM services are internet-exposed. Given the user-interaction requirement and elevated EPSS, brief administrators on unexpected file-download prompts and monitor the server for anomalous process activity.

Affected
Ivanti Endpoint Manager 2024all versions before 2024 SU3 SR1
Ivanti Endpoint Manager 2022all versions before 2022 SU8 SR2
Estimated exposure
largeon the order of tens of thousands of Ivanti EPM server deployments (10,000s of installations; each manages many more endpoints) — Estimated from Ivanti Endpoint Manager's long-established on-premises enterprise install base (tens of thousands of organizations worldwide, each running at least one management server); no public internet-exposure scan or install-count…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Insufficient filename validation in Ivanti Endpoint Manager before 2024 SU3 SR1 and 2022 SU8 SR2 allows a remote unauthenticated attacker to achieve remote code execution. User interaction is required.

Vendors
ivanti
Products
endpoint manager
Weakness
CWE-434
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.