Full Report
Ivanti warned customers today to patch their Ivanti Endpoint Manager Mobile (EPMM) software against two security vulnerabilities chained in attacks to gain remote code execution. [...]
Analysis Summary
# Vulnerability: Chained Zero-Days Leading to Remote Code Execution in Ivanti EPMM
## CVE Details
- **CVE ID:** Not explicitly detailed for the *chained* EPMM RCE vulnerability in the provided text. The text mentions other Ivanti CVEs (CVE-2025-22462, CVE-2025-22460) but not the specific ones for the EPMM RCE chain.
- **CVSS Score:** Not provided, but the context implies high severity due to chaining leading to code execution.
- **CWE:** Not specified.
## Affected Systems
- **Products:** Ivanti Endpoint Manager Mobile (EPMM) on-premises product.
- **Versions:** All vulnerable versions of on-prem EPMM (specific versions not listed).
- **Configurations:** On-premises installations are specifically targeted.
## Vulnerability Description
The vulnerability involves a chain of two zero-day flaws within the Ivanti EPMM product, which, when successfully exploited together, allow for Remote Code Execution (RCE). The nature of the chaining (e.g., which technique was chained with which) is not detailed, but the end result is control over the affected system.
## Exploitation
- **Status:** Exploited in the wild (Implied, as Ivanti is issuing urgent fixes for zero-days).
- **Complexity:** Implied to be complex due to chaining, but successful exploitation leads to RCE.
- **Attack Vector:** Likely network-based, as the product often handles remote management functions.
## Impact
- **Confidentiality:** High (Full system compromise due to RCE).
- **Integrity:** High (Full system compromise due to RCE).
- **Availability:** High (System may be taken offline or converted to malicious use).
## Remediation
### Patches
- Ivanti has released security updates/patches for the on-prem EPMM product. **Customers are urged to install the patch promptly.** Specific patch versions are not detailed in this text summary.
### Workarounds
- No specific workarounds are listed for the EPMM RCE chain in this summary text. **Immediate patching is the primary recommendation.**
## Detection
- **Indicators of Compromise (IOCs):** Not specified, but organizations should be vigilant for unusual activity related to EPMM services.
- **Detection Methods and Tools:** Organizations can use Shadowserver's tracking data as a general reference for exposed instances, though this doesn't actively detect compromise. Vulnerability scanners should be checked for specific checks related to the patched Ivanti EPMM versions.
## References
- Ivanti Advisory: hxxps://www.ivanti.com/blog/epmm-security-update
- Shadowserver instances tracking: hxxps://dashboard.shadowserver.org/statistics/iot-devices/map/?date_range=1&vendor=ivanti&model=epmm&data_set=count&scale=log
- Related Ivanti Advisory (Another Product): hxxps://www.bleepingcomputer.com/news/security/ivanti-warns-of-critical-neurons-for-itsm-auth-bypass-flaw/ (CVE-2025-22462)
- Related Ivanti Advisory (Another Product): Details on CVE-2025-22460 in Cloud Services Appliance (CSA)