CVE-2025-13659
Ivanti Endpoint Manager vulnerability analysis and mitigation

Overview

CVE-2025-13659 is an improper control of dynamically managed code resources vulnerability (CWE-913) in Ivanti Endpoint Manager (EPM) that allows a remote, unauthenticated attacker to write arbitrary files on the server, potentially leading to remote code execution (RCE). It affects all EPM 2024 versions prior to 2024 SU4 SR1, including 2024, 2024 SU1, SU2, SU3, SU3 SR1, and SU4. The vulnerability was published on December 9, 2025, with a patch released on December 11, 2025. It carries a CVSS v3.1 base score of 8.8 (High) (Ivanti Advisory, Red Hat CVE).

Technical details

The vulnerability is rooted in improper control of dynamically managed code resources (CWE-913) within Ivanti EPM's handling of network requests. Research by watchTowr Labs identified this class of vulnerability as related to the "SOAPwn" attack technique, which abuses .NET Framework HTTP client proxies and WSDL parsing to enable arbitrary file writes on the server — a mechanism that can be triggered by directing a victim's EPM server to fetch a malicious WSDL document (watchTowr Labs). Exploitation requires user interaction (UI:R), meaning an attacker must induce some form of interaction — such as a server-side request — to trigger the vulnerable code path. No authentication is required, and attack complexity is low, making the vulnerability accessible to a broad range of threat actors (Ivanti Advisory).

Impact

Successful exploitation allows an unauthenticated remote attacker to write arbitrary files to the Ivanti EPM server, which can be leveraged to achieve full remote code execution. This results in high impact to confidentiality, integrity, and availability of the affected system. Given EPM's role as an enterprise endpoint management platform with broad access to managed devices, a compromised EPM server could serve as a pivot point for lateral movement across the entire managed environment (Red Hat CVE, BleepingComputer). Reports noted that hundreds of Ivanti EPM systems were exposed online at the time of disclosure, amplifying the potential attack surface (CSO Online).

Exploitability

As of the time of disclosure, there is no public proof-of-concept exploit and no confirmed evidence of in-the-wild exploitation (Feedly). The EPSS score is approximately 0.296%, indicating a currently low but non-negligible probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog at this time. Detection plugins are available from Qualys (ID: 386197) and Nessus (ID: 278330), enabling organizations to identify vulnerable systems (Qualys, Tenable).

Exploitation steps

  1. Reconnaissance: Identify internet-facing Ivanti EPM servers running versions prior to 2024 SU4 SR1 using tools like Shodan or Censys, searching for EPM-specific service banners or web interfaces.
  2. Set up a rogue WSDL server: Host a malicious WSDL document on an attacker-controlled server. The WSDL is crafted to exploit the SOAPwn technique — abusing .NET Framework HTTP client proxy behavior to trigger arbitrary file writes when parsed by the EPM server.
  3. Trigger user interaction: Induce the EPM server or an authenticated user to initiate a request that causes the server to fetch and process the malicious WSDL document (e.g., via a crafted URL or server-side request forgery scenario).
  4. Achieve arbitrary file write: The EPM server processes the rogue WSDL and writes attacker-controlled content to a location on the server's file system, such as a web-accessible directory.
  5. Execute code: If the written file is a web shell or executable script placed in a web-accessible path, the attacker sends an HTTP request to execute it, achieving remote code execution on the EPM server (watchTowr Labs, BleepingComputer).

Indicators of compromise

  • Network: Outbound HTTP/HTTPS requests from the EPM server to unexpected external hosts (potential rogue WSDL server); unusual SOAP/WSDL-related traffic originating from the EPM server.
  • File System: Unexpected new files (especially .aspx, .php, .ashx, or script files) appearing in EPM web-accessible directories; files with recent creation timestamps not associated with legitimate updates or installations.
  • Logs: EPM application or IIS logs showing requests to unusual endpoints or referencing external WSDL URLs; errors related to SOAP proxy or WSDL parsing in application event logs.
  • Process: Unusual child processes spawned by the EPM service or IIS worker process (e.g., cmd.exe, powershell.exe, net.exe) not associated with normal EPM operations (watchTowr Labs, Qualys).

Mitigation and workarounds

Ivanti has released a patch in Ivanti Endpoint Manager version 2024 SU4 SR1, which addresses CVE-2025-13659 along with related vulnerabilities. Organizations should upgrade to this version immediately. As interim mitigations, restrict network access to the EPM server to trusted hosts only, implement egress filtering to prevent the EPM server from making outbound connections to untrusted external hosts, and monitor for suspicious file creation activity in web-accessible directories (Ivanti Advisory, Qualys).

Community reactions

The vulnerability received broad coverage from security media outlets including BleepingComputer, The Hacker News, and CSO Online, with particular attention to the hundreds of internet-exposed EPM systems identified at the time of disclosure (BleepingComputer, CSO Online). watchTowr Labs published a detailed technical write-up on the underlying "SOAPwn" vulnerability class in .NET Framework, which underpins this and related flaws in Ivanti, Barracuda, and Microsoft products (watchTowr Labs). The Belgian Centre for Cybersecurity (CCB) issued a warning urging organizations to apply the patch promptly (CCB Belgium).

Additional resources


SourceThis report was generated using AI

Related Ivanti Endpoint Manager vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-8111HIGH8.8
  • Ivanti Endpoint Manager logoIvanti Endpoint Manager
  • cpe:2.3:a:ivanti:endpoint_manager
NoNoMay 12, 2026
CVE-2026-8110HIGH7.8
  • Ivanti Endpoint Manager logoIvanti Endpoint Manager
  • cpe:2.3:a:ivanti:endpoint_manager
NoNoMay 12, 2026
CVE-2026-1603HIGH7.5
  • Ivanti Endpoint Manager logoIvanti Endpoint Manager
  • cpe:2.3:a:ivanti:endpoint_manager
YesNoFeb 10, 2026
CVE-2026-8109MEDIUM6.5
  • Ivanti Endpoint Manager logoIvanti Endpoint Manager
  • cpe:2.3:a:ivanti:endpoint_manager
NoNoMay 12, 2026
CVE-2026-1602MEDIUM6.5
  • Ivanti Endpoint Manager logoIvanti Endpoint Manager
  • cpe:2.3:a:ivanti:endpoint_manager
NoNoFeb 10, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management