High severity8.8NVD Advisory· Published Sep 9, 2025· Updated Jun 17, 2026
CVE-2025-9872
CVE-2025-9872
Description
Insufficient filename validation in Ivanti Endpoint Manager before 2024 SU3 SR1 and 2022 SU8 SR2 allows a remote unauthenticated attacker to achieve remote code execution. User interaction is required.
Affected products
16cpe:2.3:a:ivanti:endpoint_manager:*:-:*:*:*:*:*:*+ 14 more
- cpe:2.3:a:ivanti:endpoint_manager:*:-:*:*:*:*:*:*range: <2022
- cpe:2.3:a:ivanti:endpoint_manager:2022:-:*:*:*:*:*:*
- cpe:2.3:a:ivanti:endpoint_manager:2022:su1:*:*:*:*:*:*
- cpe:2.3:a:ivanti:endpoint_manager:2022:su2:*:*:*:*:*:*
- cpe:2.3:a:ivanti:endpoint_manager:2022:su3:*:*:*:*:*:*
- cpe:2.3:a:ivanti:endpoint_manager:2022:su4:*:*:*:*:*:*
- cpe:2.3:a:ivanti:endpoint_manager:2022:su5:*:*:*:*:*:*
- cpe:2.3:a:ivanti:endpoint_manager:2022:su6:*:*:*:*:*:*
- cpe:2.3:a:ivanti:endpoint_manager:2022:su7:*:*:*:*:*:*
- cpe:2.3:a:ivanti:endpoint_manager:2022:su8:*:*:*:*:*:*
- cpe:2.3:a:ivanti:endpoint_manager:2022:su8_security_release_1:*:*:*:*:*:*
- cpe:2.3:a:ivanti:endpoint_manager:2024:-:*:*:*:*:*:*
- cpe:2.3:a:ivanti:endpoint_manager:2024:su1:*:*:*:*:*:*
- cpe:2.3:a:ivanti:endpoint_manager:2024:su2:*:*:*:*:*:*
- (no CPE)range: < 2024 SU3 SR1 and < 2022 SU8 SR2
- Range: 2024 SU3 Security Release 1
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.