CVE-2025-9712 - CVE House
Back to Database
Status published High CVE-2025-9712

Insufficient filename validation in Ivanti Endpoint Manager before 2024 SU3...

Vulnerability Description

Insufficient filename validation in Ivanti Endpoint Manager before 2024 SU3 SR1 and 2022 SU8 SR2 allows a remote unauthenticated attacker to achieve remote code execution. User interaction is required.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-9712

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

Endpoint Manager
Vulnerable Versions:
2024 SU3 Security Release 1, 2022 SU8 Security Release 2

Timeline

Official Publish: September 9th, 2025
Last Modified: February 26th, 2026
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Weaknesses (CWE)