CVE-2025-9712
8.8Ivanti · Endpoint Manager
Insufficient filename validation in Ivanti Endpoint Manager allows an unauthenticated remote attacker to achieve remote code execution via file upload.
Executive summary
An unauthenticated remote code execution vulnerability in Ivanti Endpoint Manager poses a severe threat to internal infrastructure and requires immediate patching.
Vulnerability
This vulnerability involves improper filename validation, categorized as CWE-434, which allows an unauthenticated attacker to upload dangerous files to the system. While user interaction is required, successful exploitation grants the attacker remote code execution capabilities.
Business impact
The ability for an unauthenticated attacker to execute arbitrary code on an Endpoint Manager server constitutes a critical security breach. This could lead to full system compromise, unauthorized access to sensitive internal data, and the potential for lateral movement across the enterprise network. With a CVSS score of 8.8, this vulnerability is classified as High severity and necessitates urgent remediation to prevent total system compromise.
Remediation
Immediate Action: Organizations must immediately upgrade their Ivanti Endpoint Manager instances to the fixed versions, specifically 2024 SU3 SR1 or 2022 SU8 SR2, as specified by the vendor.
Proactive Monitoring: Security teams should monitor server access logs for unusual file upload activity or unexpected execution of processes originating from the management interface.
Compensating Controls: Deploy Web Application Firewall rules to inspect and block suspicious file upload requests or anomalous traffic patterns directed toward the Endpoint Manager web interface.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the high CVSS score and the critical nature of remote code execution, it is imperative that administrators prioritize the application of the vendor-provided security patches. Delaying these updates leaves the management infrastructure exposed to potential exploitation. Ensure that all affected systems are identified and updated immediately to maintain the integrity and security of the network.