CVE-2025-13662
Ivanti Endpoint Manager vulnerability analysis and mitigation

Overview

CVE-2025-13662 is an improper verification of cryptographic signatures vulnerability in the patch management component of Ivanti Endpoint Manager (EPM). It allows a remote unauthenticated attacker to execute arbitrary code, though user interaction is required. Affected versions include all EPM 2024 releases prior to 2024 SU4 SR1 (including 2024, 2024 SU1, SU2, SU3, SU3 SR1, and SU4). The vulnerability was published on December 9, 2025, with a patch released shortly after. It carries a CVSS v3.1 base score of 7.8 (High) (Ivanti Advisory, Red Hat CVE).

Technical details

The root cause is classified as CWE-347 (Improper Verification of Cryptographic Signature), specifically within the patch management component of Ivanti EPM. Because the software fails to properly validate cryptographic signatures on patch content, an attacker can supply maliciously crafted or tampered patch data that the system accepts as legitimate. The attack vector is local (AV:L) with no privileges required, but user interaction is necessary — suggesting the exploit path involves a user triggering a patch operation that processes attacker-influenced content. The Zero Day Initiative published an advisory (ZDI-25-1051) related to this vulnerability (ZDI Advisory, Ivanti Advisory).

Impact

Successful exploitation results in high impact to confidentiality, integrity, and availability — effectively enabling full system compromise on the affected endpoint. An attacker who tricks a user into initiating a patch operation could execute arbitrary code in the context of the EPM client, potentially enabling credential theft, lateral movement across managed endpoints, or deployment of malware across the enterprise environment managed by EPM. Given that Ivanti EPM is typically deployed to manage large fleets of enterprise endpoints, a successful attack could have broad organizational impact (Red Hat CVE, BleepingComputer).

Exploitability

As of the time of disclosure, there is no public proof-of-concept exploit and no confirmed evidence of in-the-wild exploitation (Feedly). The EPSS score is approximately 0.037%, indicating a currently low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Detection plugins are available from Qualys (ID: 386197) and Nessus (ID: 278330), enabling organizations to identify vulnerable systems (Qualys, Tenable).

Exploitation steps

  1. Reconnaissance: Identify organizations using Ivanti EPM 2024 versions prior to SU4 SR1 using network scanning or OSINT. CSO Online reported hundreds of EPM systems exposed online, making target identification feasible (CSO Online).
  2. Craft malicious patch content: Prepare a tampered patch package or update payload that bypasses the EPM patch management component's signature verification, exploiting the CWE-347 flaw.
  3. Deliver malicious content: Position the attacker-controlled patch content in a location reachable by the EPM client — for example, via a man-in-the-middle position on the network, a rogue update server, or by compromising a patch distribution point.
  4. Trigger user interaction: Social engineer or wait for a legitimate user or administrator to initiate a patch operation within EPM, causing the client to fetch and process the malicious patch content.
  5. Achieve code execution: The EPM client processes the unsigned or improperly signed payload without rejection, executing the attacker's arbitrary code in the context of the EPM process on the target endpoint.

Indicators of compromise

  • Network: Unexpected outbound connections from EPM-managed endpoints to unknown or external IP addresses following patch operations; EPM clients contacting non-standard or unauthorized patch distribution servers.
  • File System: Unexpected executables, scripts, or DLLs written to EPM installation or temp directories following a patch cycle; newly created files with unusual names in patch staging directories.
  • Logs: EPM client logs showing patch downloads from unexpected sources or URLs; signature verification errors or warnings in EPM logs that were subsequently ignored; unusual process execution events logged immediately after patch operations.
  • Process: Unexpected child processes spawned by the Ivanti EPM agent process (e.g., cmd.exe, powershell.exe, wscript.exe) following a patch operation; unusual network connections initiated by EPM agent processes.

Mitigation and workarounds

Ivanti has released a fix in Ivanti Endpoint Manager 2024 SU4 SR1, which addresses CVE-2025-13662 along with other vulnerabilities disclosed in the December 2025 security advisory. Organizations should upgrade to EPM 2024 SU4 SR1 immediately. As interim measures, administrators should ensure EPM clients only communicate with trusted, internal patch distribution points, monitor for anomalous patch activity, and implement network segmentation to limit the blast radius of any compromise. No specific configuration-based workaround has been publicly documented (Ivanti Advisory, BleepingComputer).

Community reactions

BleepingComputer and The Hacker News covered the disclosure as part of a broader wave of urgent patches from Ivanti, Fortinet, and SAP released in December 2025, highlighting the pattern of critical flaws in enterprise management software (BleepingComputer, The Hacker News). CSO Online noted that hundreds of Ivanti EPM systems were exposed online at the time of patching, amplifying concern about the risk window (CSO Online). The Zero Day Initiative published a coordinated advisory (ZDI-25-1051), indicating responsible disclosure involvement (ZDI Advisory). Security researchers and media broadly urged immediate patching given Ivanti's history of actively exploited vulnerabilities.

Additional resources


SourceThis report was generated using AI

Related Ivanti Endpoint Manager vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-8111HIGH8.8
  • Ivanti Endpoint Manager logoIvanti Endpoint Manager
  • cpe:2.3:a:ivanti:endpoint_manager
NoNoMay 12, 2026
CVE-2026-8110HIGH7.8
  • Ivanti Endpoint Manager logoIvanti Endpoint Manager
  • cpe:2.3:a:ivanti:endpoint_manager
NoNoMay 12, 2026
CVE-2026-1603HIGH7.5
  • Ivanti Endpoint Manager logoIvanti Endpoint Manager
  • cpe:2.3:a:ivanti:endpoint_manager
YesNoFeb 10, 2026
CVE-2026-8109MEDIUM6.5
  • Ivanti Endpoint Manager logoIvanti Endpoint Manager
  • cpe:2.3:a:ivanti:endpoint_manager
NoNoMay 12, 2026
CVE-2026-1602MEDIUM6.5
  • Ivanti Endpoint Manager logoIvanti Endpoint Manager
  • cpe:2.3:a:ivanti:endpoint_manager
NoNoFeb 10, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management