Improper Resource Management in Ivanti Endpoint Manager Exposes File Writing Vulnerability
CVE-2025-13659

8.8HIGH

Key Information:

Vendor

Ivanti

Vendor
CVE Published:
9 December 2025

Badges

📰 News Worthy

What is CVE-2025-13659?

A significant vulnerability in Ivanti Endpoint Manager allows attackers to exploit improper management of dynamically allocated code resources. This flaw enables remote, unauthenticated attackers to write arbitrary files on the server, which creates a pathway for potential execution of arbitrary code. While user interaction is needed to activate this threat, it presents a serious security risk that must be remedied to protect sensitive information and maintain system integrity.

Affected Version(s)

Endpoint Manager 2024 SU4 SR1

News Articles

Ivanti Endpoint Manager Vulnerabilities: Update Now to Prevent RCE

Ivanti EPM has critical vulnerabilities, including a 9.6 CVSS XSS flaw. Update now to prevent remote code execution and session hijacking. Learn more.

17 hours ago

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • 📰

    First article discovered by Red Hot Cyber

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-13659 : Improper Resource Management in Ivanti Endpoint Manager Exposes File Writing Vulnerability