
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-13662 is an improper verification of cryptographic signatures vulnerability in the patch management component of Ivanti Endpoint Manager (EPM). It allows a remote unauthenticated attacker to execute arbitrary code, though user interaction is required. Affected versions include all EPM 2024 releases prior to 2024 SU4 SR1 (including 2024, 2024 SU1, SU2, SU3, SU3 SR1, and SU4). The vulnerability was published on December 9, 2025, with a patch released shortly after. It carries a CVSS v3.1 base score of 7.8 (High) (Ivanti Advisory, Red Hat CVE).
The root cause is classified as CWE-347 (Improper Verification of Cryptographic Signature), specifically within the patch management component of Ivanti EPM. Because the software fails to properly validate cryptographic signatures on patch content, an attacker can supply maliciously crafted or tampered patch data that the system accepts as legitimate. The attack vector is local (AV:L) with no privileges required, but user interaction is necessary — suggesting the exploit path involves a user triggering a patch operation that processes attacker-influenced content. The Zero Day Initiative published an advisory (ZDI-25-1051) related to this vulnerability (ZDI Advisory, Ivanti Advisory).
Successful exploitation results in high impact to confidentiality, integrity, and availability — effectively enabling full system compromise on the affected endpoint. An attacker who tricks a user into initiating a patch operation could execute arbitrary code in the context of the EPM client, potentially enabling credential theft, lateral movement across managed endpoints, or deployment of malware across the enterprise environment managed by EPM. Given that Ivanti EPM is typically deployed to manage large fleets of enterprise endpoints, a successful attack could have broad organizational impact (Red Hat CVE, BleepingComputer).
As of the time of disclosure, there is no public proof-of-concept exploit and no confirmed evidence of in-the-wild exploitation (Feedly). The EPSS score is approximately 0.037%, indicating a currently low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Detection plugins are available from Qualys (ID: 386197) and Nessus (ID: 278330), enabling organizations to identify vulnerable systems (Qualys, Tenable).
cmd.exe, powershell.exe, wscript.exe) following a patch operation; unusual network connections initiated by EPM agent processes.Ivanti has released a fix in Ivanti Endpoint Manager 2024 SU4 SR1, which addresses CVE-2025-13662 along with other vulnerabilities disclosed in the December 2025 security advisory. Organizations should upgrade to EPM 2024 SU4 SR1 immediately. As interim measures, administrators should ensure EPM clients only communicate with trusted, internal patch distribution points, monitor for anomalous patch activity, and implement network segmentation to limit the blast radius of any compromise. No specific configuration-based workaround has been publicly documented (Ivanti Advisory, BleepingComputer).
BleepingComputer and The Hacker News covered the disclosure as part of a broader wave of urgent patches from Ivanti, Fortinet, and SAP released in December 2025, highlighting the pattern of critical flaws in enterprise management software (BleepingComputer, The Hacker News). CSO Online noted that hundreds of Ivanti EPM systems were exposed online at the time of patching, amplifying concern about the risk window (CSO Online). The Zero Day Initiative published a coordinated advisory (ZDI-25-1051), indicating responsible disclosure involvement (ZDI Advisory). Security researchers and media broadly urged immediate patching given Ivanti's history of actively exploited vulnerabilities.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."