CyberzSOC

Publication detail
← Back to advisories & guidance

2025-018: Zero-Day Vulnerabilities in Ivanti EPMM ↗ source

May 16, 2025 CERT-EU Advisory

Summary

An attacker could chain those vulnerabilities to achieve unauthenticated remote code execution on the vulnerable device. These vulnerabilities have been exploited in a [New] The analysis conducted by WatchTowr [3] provides significantly more information than the advisory issued by Ivanti in two key aspects: that they are related to third-party libraries. CERT-EU strongly recommends applying the update as soon as possible, prioritising Internet The vulnerability CVE-2025-4427, with a CVSS score of 5.3, is an authentication bypass in Ivanti Endpoint Manager Mobile (EPMM) allowing attackers to access protected resources without proper credentials. The vulnerability CVE-2025-4428, with a CVSS score of 7.2, is a remote code execution vulnerability in Ivanti Endpoint Manager Mobile (EPMM) allowing attackers to execute arbitrary code These two vulnerabilities could be chained to achieve unauthenticated remote code execution [New] WatchTowr’s further examination of the EPMM fix suggests that assigning two separate CVEs may be unnecessary [3]. The application’s design appears to allow for the exploitation of both vulnerabilities without requiring a valid login, implying that they could be considered as a single, more severe vulnerability - potentially critical in nature.

News Coverage

No coverage found in monitored research blogs or news feeds.

CVEs Referenced in This Publication

CVECVSSAffected
CVE-2025-4428 7.2 High Ivanti Endpoint Manager Mobile (EPMM) Ivanti Endpoint Manager Mobile (EPMM) contains a code injection vulnerability in the API component that allows an authenticated attacker to remotely …
CVE-2025-4427 5.3 Medium Ivanti Endpoint Manager Mobile (EPMM) Ivanti Endpoint Manager Mobile (EPMM) contains an authentication bypass vulnerability in the API component that allows an attacker to access protecte…

Extracted from the publication text. Each CVE links to its tracked detail page.

Vendors Named in This Publication

Each vendor links to its Known Exploited Vulnerabilities catalog page. Only vendors that appear in the KEV catalog are listed, either because the publication cites one of their KEV entries or because it names them directly.