LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2025-4428: Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability

RBRecent Breaches Vulnerability Intelligence·May 19, 2025
CVSS 7.2 · High⚠ Actively exploited (CISA KEV)
7.2
CVSS score
High
Severity
Active
CISA KEV
No
Ransomware use
Jun 9, 2025
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2025-4428 to its Known Exploited Vulnerabilities catalog on May 19, 2025, with a federal patch deadline of Jun 9, 2025 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Remote Code Execution in API component in Ivanti Endpoint Manager Mobile 12.5.0.0 and prior on unspecified platforms allows authenticated attackers to execute arbitrary code via crafted API requests.

CVE-2025-4428 is a code injection vulnerability in Ivanti Endpoint Manager Mobile (EPMM), specifically in its API component. An authenticated attacker can send crafted API requests to execute arbitrary code remotely. The issue stems from an insecure implementation of the Hibernate Validator open-source library (related to CVE-2025-35036). This matters because EPMM is used for mobile device management in enterprise environments; successful exploitation could give an attacker control over the management server and potentially the devices it oversees.

Public detail is limited to the CISA summary and CWE classification. Confirm all version ranges, exact attack prerequisites, and remediation steps against the current Ivanti vendor advisory before acting.

How it works

The weakness is classified as CWE-94 (Improper Control of Generation of Code, or Code Injection). In this case, the API component of EPMM does not properly constrain or sanitize input that is later processed by the Hibernate Validator library. An attacker who already holds valid authentication credentials can craft API requests that cause the server to generate and execute unintended code.

Because the flaw is in the API surface, the attacker does not need physical access or a separate foothold on the host; the malicious payload travels inside legitimate-looking API traffic. The CISA description emphasizes that the root cause is the insecure library integration rather than a separate logic error elsewhere in EPMM. No further exploit mechanics, sample payloads, or privilege-escalation paths are provided in the available facts, so defenders should treat any authenticated API interaction as potentially abusable until the vendor patch is applied.

Am I affected? How to find it in your systems

Ivanti Endpoint Manager Mobile (EPMM) is typically deployed as an on-premises or cloud-hosted mobile device management (MDM) platform that enrolls and configures smartphones, tablets, and other endpoints. Look for it in your asset inventory under names such as EPMM, MobileIron (legacy branding), or related Ivanti management consoles.

Telemetry signs of exploitation would include anomalous API calls that succeed after authentication, unexpected process spawning under the EPMM service account, or outbound connections initiated by the management server. Because ransomware use is not documented for this CVE, focus first on detecting unauthorized code execution rather than looking for specific ransomware indicators.

How to remediate

The primary action is to apply the vendor-supplied update that addresses CVE-2025-4428. Follow Ivanti’s published instructions exactly; CISA also directs organizations to apply mitigations per those instructions, follow BOD 22-01 guidance if the instance is cloud-hosted, or discontinue use of the product if no mitigations are available.

If you can't patch immediately

Until the official update can be installed, reduce exposure with compensating controls that limit who can reach the vulnerable API and what they can do once authenticated.

These measures do not eliminate the vulnerability; they only shrink the window of opportunity until the vendor patch is applied.

If your data may have been exposed

Actively exploited code-injection flaws in management platforms can lead to full compromise of the server and the mobile devices it manages, potentially exposing configuration data, credentials, or device inventories. If you suspect exploitation, isolate the affected system, preserve forensic evidence, and follow your incident-response plan. You can also run a free exposure scan of your email addresses against known breach data sets to determine whether related accounts have already appeared in public dumps.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedIvanti · Endpoint Manager Mobile (EPMM)
WeaknessCWE-94
CVSS base score7.2 (High)
CVSS vectorCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
PublishedMay 13, 2025
Added to CISA KEVMay 19, 2025
Federal patch deadlineJun 9, 2025
Known ransomware useNot documented
Check if your data is exposed →

References

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities