PT-2025-36744 · Ivanti · Ivanti Endpoint Manager

Published

2025-09-09

·

Updated

2025-10-20

·

CVE-2025-9872

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Ivanti Endpoint Manager versions prior to 2024 SU3 SR1 and prior to 2022 SU8 SR2
Description The issue involves insufficient filename validation in Ivanti Endpoint Manager. This allows a remote, unauthenticated attacker to execute arbitrary code. User interaction is required for exploitation. The vulnerability stems from the ability to upload files of dangerous types due to a lack of proper filename validation.
Recommendations Ivanti Endpoint Manager versions prior to 2024 SU3 SR1 should be updated. Ivanti Endpoint Manager versions prior to 2022 SU8 SR2 should be updated.

Fix

RCE

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

BDU:2025-11233
CVE-2025-9872
ZDI-25-952

Affected Products

Ivanti Endpoint Manager