Article Details
Scrape Timestamp (UTC): 2025-05-14 04:06:18.532
Source: https://thehackernews.com/2025/05/ivanti-patches-epmm-vulnerabilities.html
Original Article Text
Click to Toggle View
Ivanti Patches EPMM Vulnerabilities Exploited for Remote Code Execution in Limited Attacks. Ivanti has released security updates to address two security flaws in Endpoint Manager Mobile (EPMM) software that have been chained in attacks to gain remote code execution. The vulnerabilities in question are listed below - The flaws impact the following versions of the product - Ivanti, which credited CERT-EU for reporting the issues, said it's "aware of a very limited number of customers who have been exploited at the time of disclosure" and that the vulnerabilities are "associated with two open-source libraries integrated into EPMM." The company, however, did not disclose the names of the impacted libraries. It's also not known what other software applications relying on the two libraries could be affected. Furthermore, the company said it's still investigating the cases, and that it does not have reliable indicators of compromise associated with the malicious activity. "The risk to customers is significantly reduced if they already filter access to the API using either the built-in Portal ACLs functionality or an external web application firewall," Ivanti noted. "The issue only affects the on-prem EPMM product. It is not present in Ivanti Neurons for MDM, Ivanti's cloud-based unified endpoint management solution, Ivanti Sentry, or any other Ivanti products." Separately, Ivanti has also shipped patches to contain an authentication bypass flaw in on-premise versions of Neurons for ITSM (CVE-2025-22462, CVSS score: 9.8) that could allow a remote unauthenticated attacker to gain administrative access to the system. There is no evidence that the security defect has been exploited in the wild. With zero-days in Ivanti appliances becoming a lightning rod for threat actors in recent years, it's imperative that users move quickly to update their instances to the latest versions for optimal protection.
Daily Brief Summary
Ivanti has issued updates for two critical vulnerabilities in its Endpoint Manager Mobile (EPMM) software that enable remote code execution.
These vulnerabilities were linked to two open-source libraries used in EPMM, though the specific libraries weren't disclosed.
A very limited number of customers have reportedly been affected by these exploits, according to Ivanti.
The vulnerabilities affect only the on-premises version of EPMM and not other Ivanti products like Ivanti Neurons for MDM or Ivanti Sentry.
Ivanti recommends that the risk can be significantly mitigated by filtering access to the API via built-in Portal ACLs or an external web application firewall.
Additionally, Ivanti released patches for an unrelated authentication bypass issue in on-premise Neurons for ITSM, which also poses severe risks but has not been exploited.
Users are encouraged to update their Ivanti software instances promptly to prevent potential exploits by threat actors.