CVE-2025-13659HIGH 8.8EPSS p72.9%

CVE-2025-13659CVE-2025-13659

Description

Improper control of dynamically managed code resources in Ivanti Endpoint Manager prior to version 2024 SU4 SR1 allows a remote, unauthenticated attacker to write arbitrary files on the server, potentially leading to remote code execution. User interaction is required.

Scoring

CVSS 3.18.8 (HIGH)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS1.62% probability of exploitation · percentile 72.9% · 2026-06-18T12:00:27Z
Published2025-12-09
Last modified2025-12-11

Underlying weaknesses· 1

CWE-913

References

  1. https://forums.ivanti.com/s/article/Security-Advisory-EPM-December-2025-for-EPM-2024

1

TypeTargetConfidenceTier
WeaknessImproper Control of Dynamically-Managed Code Resourcescwe-9130%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CVE
CVE-2025-13661
CVE
CVE-2025-9713
CVE
CVE-2025-9712
CVE
CVE-2025-9872
CVE
Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability
CVE
Ivanti Endpoint Manager Cloud Service Appliance (EPM CSA) Code Injection Vulnerability
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.