CVE-2025-6770
Ivanti Endpoint Manager Mobile vulnerability analysis and mitigation

Overview

CVE-2025-6770 is an OS command injection vulnerability in Ivanti Endpoint Manager Mobile (EPMM) that allows a remote authenticated attacker with high privileges to achieve remote code execution. The vulnerability affects EPMM versions before 12.3.0.3, versions 12.4.0.0–12.4.0.2, and versions 12.5.0.0–12.5.0.1. It was published on July 8, 2025, with a patch released on July 11, 2025. The CVSS v3.1 base score is 7.2 (High) (Ivanti Advisory, Red Hat CVE).

Technical details

The root cause is improper neutralization of special elements used in OS commands (CWE-78), a classic OS command injection flaw. An attacker with high-privilege remote access can craft malicious input that is passed unsanitized to an underlying OS command interpreter, resulting in arbitrary command execution on the EPMM server. Exploitation requires network access and a valid high-privilege account, but no user interaction is needed. The vulnerability was assigned by Ivanti and is tracked alongside a related issue CVE-2025-6771 in the same advisory (Ivanti Advisory, Red Hat CVE).

Impact

Successful exploitation allows a privileged remote attacker to execute arbitrary OS commands on the EPMM server, resulting in full compromise of confidentiality, integrity, and availability. An attacker could exfiltrate sensitive mobile device management data (including enrolled device credentials and configurations), modify or delete critical system data, or disrupt EPMM service availability. Given EPMM's role as a mobile device management platform, compromise could facilitate lateral movement to managed endpoints or corporate infrastructure (Ivanti Advisory, Red Hat CVE).

Exploitability

As of the time of disclosure, there is no public proof-of-concept exploit and no confirmed evidence of in-the-wild exploitation (Red Hat CVE). The EPSS score is approximately 0.0101 (roughly 1%), indicating a currently low but non-negligible probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog at this time. Exploitation requires a high-privilege authenticated account, which somewhat limits the attack surface compared to unauthenticated vulnerabilities (Ivanti Advisory).

Exploitation steps

  1. Reconnaissance: Identify internet-facing Ivanti EPMM instances running versions before 12.3.0.3, 12.4.0.3, or 12.5.0.2 using tools like Shodan or Censys, searching for EPMM login portals.
  2. Credential Acquisition: Obtain high-privilege credentials for the EPMM instance through phishing, credential stuffing, or prior compromise of an administrator account.
  3. Authentication: Log in to the EPMM administrative interface using the acquired high-privilege credentials.
  4. Inject OS Command: Identify the vulnerable input field or API endpoint that passes user-supplied data to an OS command. Craft a payload containing OS command delimiters (e.g., ;, &&, |) followed by the desired command (e.g., a reverse shell or data exfiltration command).
  5. Achieve Remote Code Execution: Submit the crafted payload; the server executes the injected OS command in the context of the EPMM service account, granting the attacker arbitrary command execution on the host (Ivanti Advisory).

Indicators of compromise

  • Network: Unexpected outbound connections from the EPMM server to external IPs, particularly on non-standard ports; unusual DNS lookups originating from the EPMM host.
  • Logs: EPMM application or web server logs showing anomalous API requests with special characters (;, &&, |, backticks) in parameter values; authentication events for high-privilege accounts at unusual times or from unexpected source IPs.
  • Process: Unexpected child processes spawned by the EPMM Java or application process (e.g., /bin/sh, bash, curl, wget, python, nc); new cron jobs or scheduled tasks created under the EPMM service account.
  • File System: New or modified files in EPMM installation directories, particularly scripts or binaries not part of the standard installation; presence of web shells or reverse shell scripts.

Mitigation and workarounds

Ivanti has released patched versions addressing CVE-2025-6770: upgrade to EPMM 12.3.0.3, 12.4.0.3, or 12.5.0.2 (or later) depending on your current release branch. Organizations should prioritize upgrading to the latest patched version as the primary remediation. As interim measures, restrict access to the EPMM administrative interface to trusted IP ranges, audit and minimize high-privilege accounts, and monitor for suspicious activity. The Canadian Centre for Cyber Security also issued an advisory (AV25-405) recommending prompt patching (Ivanti Advisory, Ivanti Blog, CCCS Advisory).

Community reactions

Ivanti published a security advisory and a July 2025 security update blog post covering CVE-2025-6770 alongside CVE-2025-6771 (Ivanti Blog). The Canadian Centre for Cyber Security issued advisory AV25-405 recommending immediate patching (CCCS Advisory). Security community members on Mastodon (infosec.exchange) noted the disclosure shortly after publication. CyberSecurityNews also covered the vulnerabilities, and Tenable released detection plugins (Nessus plugin 241979) for the flaw (CyberSecurityNews, Tenable).

Additional resources


SourceThis report was generated using AI

Related Ivanti Endpoint Manager Mobile vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-5788CRITICAL9.8
  • Ivanti Endpoint Manager Mobile logoIvanti Endpoint Manager Mobile
  • cpe:2.3:a:ivanti:endpoint_manager_mobile
NoYesMay 07, 2026
CVE-2026-7821CRITICAL9.1
  • Ivanti Endpoint Manager Mobile logoIvanti Endpoint Manager Mobile
  • cpe:2.3:a:ivanti:endpoint_manager_mobile
NoYesMay 07, 2026
CVE-2026-5787CRITICAL9.1
  • Ivanti Endpoint Manager Mobile logoIvanti Endpoint Manager Mobile
  • cpe:2.3:a:ivanti:endpoint_manager_mobile
NoYesMay 07, 2026
CVE-2026-5786HIGH8.8
  • Ivanti Endpoint Manager Mobile logoIvanti Endpoint Manager Mobile
  • cpe:2.3:a:ivanti:endpoint_manager_mobile
NoYesMay 07, 2026
CVE-2026-6973HIGH7.2
  • Ivanti Endpoint Manager Mobile logoIvanti Endpoint Manager Mobile
  • cpe:2.3:a:ivanti:endpoint_manager_mobile
YesYesMay 07, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management