- Ivanti patched two deficiencies that were tied to Mount RCE -attack
- A “limited number” of businesses were allegedly compromised
- Only on-prem products are affected
Ivanti has released a patch to two vulnerabilities in its Endpoint Manager Mobile (EPMM) software that has allegedly been linked to Remote Code Execution (RCE) attacks in nature.
The vulnerabilities are traced as CVE-2025-4427 and CVE-2025-4428. The former is an approval compass in EPMMS API, giving threat players access to protected resources. It was awarded to a medium-difficult score of 5.3.
The latter is a RCE vulnerability that is utilized through malicious designed API requests. This one got a score with high difficulty (7.2/10).
Ivanti says it has seen it abused in attack: “When tied together, successful exploitation can lead to unauthorized remote code execution,” the company said in a security advice. “We are aware of a very limited number of customers whose solution has been utilized at the time of the reveal.”
To solve the problem, users must install Ivanti Endpoint Manager Mobile 11.12.0.5, 12.3.0.2, 12.4.0.2 or 12.5.0.1.
“The problem only affects the on-the-premium EPMM product. It is not present in Ivanti neurons for MDM, Ivanti’s cloud-based Unified Endpoint Management Solution, Ivanti Sentry or other Ivanti products,” the company further explained. “We encourage all customers who use the On-Prem EPMM product to immediately install patch.”
Ivantis EPMM software is a popular solution across different industries, including healthcare, education, logistics, manufacturing and government. According to Shadows server, there are hundreds of vulnerable cases at the moment, mostly in Germany (992), but with a significant number in the United States (418).
Those who cannot use the patch at this time can implement different solutions. Ivanti said these users should follow guidance for best practice or filter access to the API using either the built -in portal ACL’s functionality or an external waf. More details of using the portal’s ACL functionality can be found here.
Via Bleeping computer