Close Menu
globalcrimedesk.comglobalcrimedesk.com
    What's Hot

    Why were Pete Rose, Shoeless Joe Jackson banned from Baseball Hall of Fame? | Baseball News

    Saudi CubeSat gets golden ticket on doomed SLS rocket • The Register

    How Tariffs Destabilize an Already Dangerous World

    Facebook X (Twitter) Instagram
    Trending
    • Why were Pete Rose, Shoeless Joe Jackson banned from Baseball Hall of Fame? | Baseball News
    • Saudi CubeSat gets golden ticket on doomed SLS rocket • The Register
    • How Tariffs Destabilize an Already Dangerous World
    • Urgent ‘do not drink’ warning issued for tap water in UK region over contamination fears
    • What to know about Menendez brothers’ case and when could they be released
    • North Korean IT Workers Are Being Exposed on a Massive Scale
    • It’s Been a Minute : NPR
    • Reece Galbraith jailed over blast deaths
    Facebook X (Twitter) Instagram
    globalcrimedesk.comglobalcrimedesk.com
    • Home
    • Cyber
    • Global
    • Law
    • Mafia
    • Prevention
    • Scandals
    • Terror
    • Trafficking
    globalcrimedesk.comglobalcrimedesk.com
    Home»Cyber»Ivanti fixes EPMM zero-days chained in code execution attacks
    Cyber

    Ivanti fixes EPMM zero-days chained in code execution attacks

    mediamillion1000@gmail.comBy [email protected]May 14, 2025No Comments3 Mins Read
    Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
    Follow Us
    Google News Flipboard
    Ivanti fixes EPMM zero-days chained in code execution attacks
    Share
    Facebook Twitter LinkedIn Pinterest Email Copy Link

    Ivanti fixes EPMM zero-days chained in code execution attacks

    Ivanti warned customers today to patch their Ivanti Endpoint Manager Mobile (EPMM) software against two security vulnerabilities chained in attacks to gain remote code execution.

    “Ivanti has released updates for Endpoint Manager Mobile (EPMM) which addresses one medium and one high severity vulnerability,” the company said.

    “When chained together, successful exploitation could lead to unauthenticated remote code execution. We are aware of a very limited number of customers whose solution has been exploited at the time of disclosure.”

    The first security flaw (CVE-2025-4427) is an authentication bypass in EPMM’s API component, allowing attackers to access protected resources on vulnerable devices. The second (tracked as CVE-2025-4428) is a remote code execution vulnerability that allows threat actors to execute arbitrary code on targeted systems via maliciously crafted API requests.

    Ivanti says customers can mitigate the two zero-day flaws by installing Ivanti Endpoint Manager Mobile 11.12.0.5, 12.3.0.2, 12.4.0.2, or 12.5.0.1.

    The company added that, while it’s still investigating these attacks and can’t provide indicators of compromise, customers should reach out to the support team for further guidance.

    While Ivanti said the two vulnerabilities are “associated” with two open-source libraries used by EPMM, it didn’t share their names in the advisory. A spokesperson directed BleepingComputer to today’s advisory for further information.

    “The issue only affects the on-prem EPMM product. It is not present in Ivanti Neurons for MDM, Ivanti’s cloud-based unified endpoint management solution, Ivanti Sentry, or any other Ivanti products,” Ivanti added in a separate advisory. “We urge all customers using the on-prem EPMM product to promptly install the patch.”

    The Shadowserver threat monitoring platform currently tracks hundreds of Ivanti EPMM instances exposed online, most in Germany (992) and the United States (418).

    Ivanti EPMM instances exposed online
    Ivanti EPMM instances exposed online (Shadowserver)

    ​Today, Ivanti also released security updates to address a critical authentication bypass vulnerability (CVE-2025-22462) impacting its Neurons for ITSM IT service management solution that can let unauthenticated attackers gain administrative access.

    It also urged customers to patch a default credentials flaw (CVE-2025-22460) in its Cloud Services Appliance (CSA) that lets local authenticated attackers escalate privileges on vulnerable systems.

    In recent years, multiple other security vulnerabilities have been exploited in zero-day attacks targeting Ivanti’s VPN appliances and ICS, IPS, and ZTA gateways.

    The FBI and CISA also warned in a joint advisory issued in January that threat actors are still exploiting months-old Ivanti Cloud Service Appliances (CSA) security vulnerabilities to breach vulnerable networks.

    Red Report 2025

    Based on an analysis of 14M malicious actions, discover the top 10 MITRE ATT&CK techniques behind 93% of attacks and how to defend against them.

    Attacks chained Code EPMM execution fixes Ivanti zerodays
    Follow on Google News Follow on Flipboard
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
    Previous ArticleDonald Trump says lifting sanctions on Syria ‘gives them a chance of greatness’ – US politics live | US news
    Next Article Trump meets Syria’s interim president al-Sharaa : NPR
    [email protected]
    • Website

    Related Posts

    Saudi CubeSat gets golden ticket on doomed SLS rocket • The Register

    May 14, 2025

    North Korean IT Workers Are Being Exposed on a Massive Scale

    May 14, 2025

    Post Office finally throttles delayed in-house EPOS project • The Register

    May 14, 2025
    Add A Comment
    Leave A Reply Cancel Reply

    Latest Posts

    Why were Pete Rose, Shoeless Joe Jackson banned from Baseball Hall of Fame? | Baseball News

    Saudi CubeSat gets golden ticket on doomed SLS rocket • The Register

    How Tariffs Destabilize an Already Dangerous World

    Urgent ‘do not drink’ warning issued for tap water in UK region over contamination fears

    Trending Posts

    Why were Pete Rose, Shoeless Joe Jackson banned from Baseball Hall of Fame? | Baseball News

    May 14, 2025

    Saudi CubeSat gets golden ticket on doomed SLS rocket • The Register

    May 14, 2025

    How Tariffs Destabilize an Already Dangerous World

    May 14, 2025

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    News

    • Cyber
    • Global
    • Law
    • Mafia
    • Prevention

    Company

    • About Us
    • Disclaimer
    • Get In Touch
    • Privacy policy
    • Terms & Condition
    Recent Posts
    • Why were Pete Rose, Shoeless Joe Jackson banned from Baseball Hall of Fame? | Baseball News
    • Saudi CubeSat gets golden ticket on doomed SLS rocket • The Register

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    © 2025 globalcrimedesk. Designed by Pro.
    Facebook X (Twitter) Pinterest Vimeo WhatsApp TikTok Instagram

    Type above and press Enter to search. Press Esc to cancel.