Improper Resource Management in Ivanti Endpoint Manager Exposes File Writing Vulnerability
CVE-2025-13659

8.8HIGH

Key Information:

Vendor

Ivanti

Vendor
CVE Published:
9 December 2025

Badges

๐Ÿ“ฐ News Worthy

What is CVE-2025-13659?

A significant vulnerability in Ivanti Endpoint Manager allows attackers to exploit improper management of dynamically allocated code resources. This flaw enables remote, unauthenticated attackers to write arbitrary files on the server, which creates a pathway for potential execution of arbitrary code. While user interaction is needed to activate this threat, it presents a serious security risk that must be remedied to protect sensitive information and maintain system integrity.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Endpoint Manager 2024 SU4 SR1

News Articles

Ivanti Endpoint Manager Vulnerabilities: Update Now to Prevent RCE

Ivanti EPM has critical vulnerabilities, including a 9.6 CVSS XSS flaw. Update now to prevent remote code execution and session hijacking. Learn more.

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • ๐Ÿ“ฐ

    First article discovered by Red Hot Cyber

  • Vulnerability published

  • Vulnerability Reserved

.