CVE-2025-13659 Details
Description
Improper control of dynamically managed code resources in Ivanti Endpoint Manager prior to version 2024 SU4 SR1 allows a remote, unauthenticated attacker to write arbitrary files on the server, potentially leading to remote code execution. User interaction is required.
A vulnerability in Ivanti Endpoint Manager (EPM) prior to version 2024 SU4 SR1 allows remote, unauthenticated attackers to write arbitrary files on the server, potentially leading to remote code execution. This issue arises from improper control of dynamically managed code resources. Exploitation of this vulnerability requires user interaction and connecting to an untrusted core server.
Users can upgrade to Ivanti Endpoint Manager 2024 SU4 SR1, available through the Ivanti License System. This update applies to EPM 2024 SU4 core consoles and remote consoles.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Dec 10, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://forums.ivanti.com/s/article/Security-Advisory-EPM-December-2025-for-EPM-2024 | ivanti | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-913 | Improper Control of Dynamically-Managed Code Resources | ivanti |
Affected Products
| Product | Versions |
|---|---|
| ivanti endpoint manager | < 2024 2024 - 2024 su1 2024 su2 2024 su3 2024 su3_security_release_1 2024 su4 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | ivanti |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Dec 11, 2025 | Initial Analysis | [email protected] |
| Dec 9, 2025 | New CVE Received | ivanti |