CVE-2025-9712 Details
Description
Insufficient filename validation in Ivanti Endpoint Manager before 2024 SU3 SR1 and 2022 SU8 SR2 allows a remote unauthenticated attacker to achieve remote code execution. User interaction is required.
A remote code execution vulnerability has been identified in Ivanti Endpoint Manager (EPM) versions 2022 SU8 Security Update 1 and prior, as well as in EPM 2024 SU3 and prior. This vulnerability arises from insufficient filename validation, allowing remote unauthenticated attackers to execute code. Exploitation of this issue requires user interaction.
Users can upgrade to Ivanti Endpoint Manager 2024 SU3 Security Release 1 or Ivanti Endpoint Manager 2022 SU8 Security Release 2. These versions are available for download in the Ivanti License System (ILS).
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Sep 10, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://forums.ivanti.com/s/article/Security-Advisory-September-2025-for-Ivanti-EPM-2024-SU3-and-EPM-2022-SU8 | ivanti | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-434 | Unrestricted Upload of File with Dangerous Type | ivanti |
Affected Products
| Product | Versions |
|---|---|
| ivanti endpoint manager | < 2022 2022 - 2022 su1 2022 su2 2022 su3 2022 su4 2022 su5 2022 su6 2022 su7 2022 su8 2022 su8_security_release_1 2024 - 2024 su1 2024 su2 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | ivanti |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Oct 10, 2025 | Initial Analysis | [email protected] |
| Sep 9, 2025 | CVE Modified | ivanti |
| Sep 9, 2025 | New CVE Received | ivanti |