CyberHappenings logo

Track cybersecurity events as they unfold. Sourced timelines. Filter, sort, and browse. Fast, privacy‑respecting. No invasive ads, no tracking.

Unpatched Ivanti Endpoint Manager Vulnerabilities Disclosed by ZDI

First reported
Last updated
1 unique sources, 1 articles

Summary

Hide ▲

Thirteen unpatched vulnerabilities in Ivanti Endpoint Manager have been disclosed by Trend Micro’s Zero Day Initiative (ZDI). One flaw allows local privilege escalation, while the remaining 12 enable remote code execution (RCE). The vulnerabilities were reported to Ivanti in November 2024 and June 2025, respectively. Ivanti has not yet released patches for these high-severity defects, which have CVSS scores ranging from 7.2 to 8.8. The vulnerabilities affect various components and methods within Ivanti Endpoint Manager, including the AgentPortal service, Report_RunPatch, MP_Report_Run2, DBDR, and others. Exploitation of these flaws requires authentication for most, but one RCE vulnerability can be exploited with admin credentials or by convincing a user to open a malicious file. ZDI advises restricting interaction with the product as the primary mitigation strategy. Ivanti has acknowledged the issues but has not provided a public statement on the delay in patching.

Timeline

  1. 10.10.2025 12:45 1 articles · 5h ago

    ZDI Discloses 13 Unpatched Ivanti Endpoint Manager Vulnerabilities

    Thirteen unpatched vulnerabilities in Ivanti Endpoint Manager have been disclosed by ZDI. One flaw allows local privilege escalation, while the remaining 12 enable remote code execution (RCE). The vulnerabilities were reported to Ivanti in November 2024 and June 2025, respectively. Ivanti has not yet released patches for these high-severity defects, which have CVSS scores ranging from 7.2 to 8.8. The vulnerabilities affect various components and methods within Ivanti Endpoint Manager, including the AgentPortal service, Report_RunPatch, MP_Report_Run2, DBDR, and others. Exploitation of these flaws requires authentication for most, but one RCE vulnerability can be exploited with admin credentials or by convincing a user to open a malicious file. ZDI advises restricting interaction with the product as the primary mitigation strategy. Ivanti has acknowledged the issues but has not provided a public statement on the delay in patching.

    Show sources

Information Snippets