OS Command Injection Vulnerability in Ivanti Endpoint Manager Mobile
CVE-2025-6771

7.2HIGH

Key Information:

Vendor

Ivanti

Vendor
CVE Published:
8 July 2025

Badges

๐Ÿ“ˆ Trended๐Ÿ“ˆ Score: 1,400๐Ÿ‘พ Exploit Exists๐Ÿ“ฐ News Worthy

What is CVE-2025-6771?

CVE-2025-6771 is a significant vulnerability identified in Ivanti Endpoint Manager Mobile (EPMM), specifically versions prior to 12.5.0.2, 12.4.0.3, and 12.3.0.3. This vulnerability is characterized as an OS command injection flaw that allows a remote authenticated attacker with elevated privileges to execute arbitrary commands on the underlying operating system. The impact of this vulnerability is serious, as it may enable attackers to gain full control over affected systems, potentially leading to unauthorized access to sensitive data and resources. Organizations utilizing Ivanti EPMM for mobile device management must be aware of the risks presented by this vulnerability, as it could facilitate various malicious activities, including data breaches and further exploits within the network.

Potential impact of CVE-2025-6771

  1. Remote Code Execution: The vulnerability allows attackers to execute arbitrary commands on the system, which can lead to complete system compromise and unauthorized access to sensitive information.

  2. Escalation of Privileges: Given that the flaw requires high privileges to exploit, attackers with compromised credentials can leverage this vulnerability to further escalate their access within the network, leading to wider security breaches.

  3. Increased Attack Surface: Organizations that fail to address this vulnerability could face increased exposure to future attacks, especially if attackers exploit it as a foothold to launch more sophisticated cyber operations.

Affected Version(s)

Endpoint Manager Mobile 12.5.0.2

Endpoint Manager Mobile 12.4.0.3

Endpoint Manager Mobile 12.3.0.3

News Articles

Ivanti Endpoint Manager Mobile Vulnerabilities Let Attackers Execute Remote Code

Ivanti disclosed two high-severity vulnerabilities in its Endpoint Manager Mobile (EPMM) product, which could allow remote attackers to execute code on affected systems.

1 month ago

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • ๐Ÿ“ˆ

    Vulnerability started trending

  • ๐Ÿ‘พ

    Exploit known to exist

  • ๐Ÿ“ฐ

    First article discovered by CyberSecurityNews

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-6771 : OS Command Injection Vulnerability in Ivanti Endpoint Manager Mobile