Close Menu
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
What's Hot

The science behind antibacterial coatings

UBC uses benchtop reactors to enhance nuclear fusion reactions

The former developer jailed for four years for obstructing an Ohio employer with kill switch malware

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
Fyself News
Home » IVANTI Patch EPMM Vulnerability was exploited to remote code execution in limited attacks
Identity

IVANTI Patch EPMM Vulnerability was exploited to remote code execution in limited attacks

userBy userMay 14, 2025No Comments2 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

May 14, 2025Ravi LakshmananVulnerability/Endpoint Security

Ivanti has released a security update to address two security flaws in Endpoint Manager Mobile (EPMM) software that was taken to an attack to gain remote code execution.

The vulnerabilities in question are listed below –

CVE-2025-4427 (CVSS score: 5.3) – Authentication bypass attackers can access protected resources without proper credentials on IVANTI Endpoint Manager mobile CVE-2025-4428 (CVSS score: 7.2)

Cybersecurity

Defects affect the next version of the product –

11.12.0.4 and previous (fixed to 11.12.0.5) 12.3.0.1 and Prior (fixed to 12.3.0.2) 12.4.0.1 and Front (fixed to 12.4.0.2) 12.5.0.0 and Front (fixed to 12.5.0.1)

Ivanti praised Cert-EU for reporting the issue, but said it “recognizes a very limited number of customers that were exploited during disclosure,” and that the vulnerability was “related to two open source libraries integrated into EPMM.”

However, the company did not disclose the names of the affected libraries. I also don’t know that other software applications that rely on the two libraries may be affected. Additionally, the company is still investigating cases and said it does not have a reliable indicator of compromise related to malicious activities.

“Already filtering access to APIs using either the built-in portal ACLS feature or the external web application firewall will significantly reduce the risk to customers,” Ivanti said.

“This issue only affects ONPREM EPMM products. It is not present in Ivanti neurons in MDM, Ivanti’s cloud-based integrated endpoint management solutions, Ivanti Sentry, or other Ivanti products.”

Cybersecurity

Apart from that, Ivanti has also shipped patches containing authentication bypass defects to the on-premises version of neurons in ITSM (CVE-2025-22462, CVSS score: 9.8). There is no evidence that security flaws are being exploited in the wild.

With zero-days on Ivanti appliances becoming a lightning bolt for threat actors in recent years, it is essential that users move quickly to update their instances to the latest version for optimal protection.

Did you find this article interesting? Follow us on Twitter and LinkedIn to read exclusive content you post.

Source link

Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleThe Trump administration will cut another $450 million with Harvard grants. Donald Trump News
Next Article Fortinet Patches CVE-2025-32756 Zero-Day RCE Fault exploited in Fortivoice System
user
  • Website

Related Posts

The former developer jailed for four years for obstructing an Ohio employer with kill switch malware

August 22, 2025

A Pre-Auth Exploit chain found in Commvault could allow remote code execution attacks

August 21, 2025

Cybercriminals Deploy Cornflake.v3 Backdoor Clickfix Tactics and Fake Captcha Pages

August 21, 2025
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

The science behind antibacterial coatings

UBC uses benchtop reactors to enhance nuclear fusion reactions

The former developer jailed for four years for obstructing an Ohio employer with kill switch malware

Openai’s lawyers question the role of meta in Elon Musk’s $97 billion purchase bid

Trending Posts

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

Smarter Healthcare Starts Now: The Power of Integrated Medical Devices

The Genius of Frustration: Tim Berners-Lee on Creating the Internet We Know

What’s Wrong with the Web? Tim Berners-Lee Speaks Out in Rare Interview

The Next Frontier: NYC Island Becomes Epicenter for Climate Solutions

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2025 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.