
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-13659 is an improper control of dynamically managed code resources vulnerability (CWE-913) in Ivanti Endpoint Manager (EPM) that allows a remote, unauthenticated attacker to write arbitrary files on the server, potentially leading to remote code execution (RCE). It affects all EPM 2024 versions prior to 2024 SU4 SR1, including 2024, 2024 SU1, SU2, SU3, SU3 SR1, and SU4. The vulnerability was published on December 9, 2025, with a patch released on December 11, 2025. It carries a CVSS v3.1 base score of 8.8 (High) (Ivanti Advisory, Red Hat CVE).
The vulnerability is rooted in improper control of dynamically managed code resources (CWE-913) within Ivanti EPM's handling of network requests. Research by watchTowr Labs identified this class of vulnerability as related to the "SOAPwn" attack technique, which abuses .NET Framework HTTP client proxies and WSDL parsing to enable arbitrary file writes on the server — a mechanism that can be triggered by directing a victim's EPM server to fetch a malicious WSDL document (watchTowr Labs). Exploitation requires user interaction (UI:R), meaning an attacker must induce some form of interaction — such as a server-side request — to trigger the vulnerable code path. No authentication is required, and attack complexity is low, making the vulnerability accessible to a broad range of threat actors (Ivanti Advisory).
Successful exploitation allows an unauthenticated remote attacker to write arbitrary files to the Ivanti EPM server, which can be leveraged to achieve full remote code execution. This results in high impact to confidentiality, integrity, and availability of the affected system. Given EPM's role as an enterprise endpoint management platform with broad access to managed devices, a compromised EPM server could serve as a pivot point for lateral movement across the entire managed environment (Red Hat CVE, BleepingComputer). Reports noted that hundreds of Ivanti EPM systems were exposed online at the time of disclosure, amplifying the potential attack surface (CSO Online).
As of the time of disclosure, there is no public proof-of-concept exploit and no confirmed evidence of in-the-wild exploitation (Feedly). The EPSS score is approximately 0.296%, indicating a currently low but non-negligible probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog at this time. Detection plugins are available from Qualys (ID: 386197) and Nessus (ID: 278330), enabling organizations to identify vulnerable systems (Qualys, Tenable).
.aspx, .php, .ashx, or script files) appearing in EPM web-accessible directories; files with recent creation timestamps not associated with legitimate updates or installations.cmd.exe, powershell.exe, net.exe) not associated with normal EPM operations (watchTowr Labs, Qualys).Ivanti has released a patch in Ivanti Endpoint Manager version 2024 SU4 SR1, which addresses CVE-2025-13659 along with related vulnerabilities. Organizations should upgrade to this version immediately. As interim mitigations, restrict network access to the EPM server to trusted hosts only, implement egress filtering to prevent the EPM server from making outbound connections to untrusted external hosts, and monitor for suspicious file creation activity in web-accessible directories (Ivanti Advisory, Qualys).
The vulnerability received broad coverage from security media outlets including BleepingComputer, The Hacker News, and CSO Online, with particular attention to the hundreds of internet-exposed EPM systems identified at the time of disclosure (BleepingComputer, CSO Online). watchTowr Labs published a detailed technical write-up on the underlying "SOAPwn" vulnerability class in .NET Framework, which underpins this and related flaws in Ivanti, Barracuda, and Microsoft products (watchTowr Labs). The Belgian Centre for Cybersecurity (CCB) issued a warning urging organizations to apply the patch promptly (CCB Belgium).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."