CVE-2025-9712
largeUnauthenticated RCE via Filename Validation Flaw in Ivanti Endpoint Manager
CVE-2025-9712 is a remote code execution vulnerability in Ivanti Endpoint Manager caused by insufficient filename validation (CWE-434), meaning files with crafted or unsafe names are not properly checked by the product. A remote, unauthenticated attacker can trigger the flaw over the network, but exploiting it requires some user interaction (CVSS:3.1 AV:N/AC:L/PR:N/UI:R, score 8.8 High). Successful exploitation gives the attacker code execution with high impact on confidentiality, integrity, and availability on the affected Endpoint Manager installation. Organizations running Ivanti Endpoint Manager 2024 before SU3 SR1 or the 2022 line before SU8 SR2 are affected. No public proof-of-concept or confirmed in-the-wild exploitation is known, but EPSS assigns a 20.5% probability of exploitation within 30 days (97th percentile), indicating elevated near-term risk.
What to do: Upgrade Ivanti Endpoint Manager 2024 to SU3 SR1 (or later) and Endpoint Manager 2022 to SU8 SR2 (or later). Restrict network access to the Endpoint Manager server from untrusted networks and check whether any EPM services are internet-exposed. Given the user-interaction requirement and elevated EPSS, brief administrators on unexpected file-download prompts and monitor the server for anomalous process activity.
| Ivanti Endpoint Manager 2024 | all versions before 2024 SU3 SR1 |
| Ivanti Endpoint Manager 2022 | all versions before 2022 SU8 SR2 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Insufficient filename validation in Ivanti Endpoint Manager before 2024 SU3 SR1 and 2022 SU8 SR2 allows a remote unauthenticated attacker to achieve remote code execution. User interaction is required.
- Vendors
- ivanti
- Products
- endpoint manager
- Weakness
- CWE-434
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.