← Back to Feed
Malicious Listener for Ivanti Endpoint Mobile Management Systems
CVE-2025-4427CVE-2025-4428
September 17, 2025 · CISA Advisories · Severity: HIGH
CISA obtained two sets of malware from an organization compromised by threat actors exploiting vulnerabilities in Ivanti Endpoint Manager Mobile. The malware contains loaders for malicious listeners that enable arbitrary code execution on the compromised server. Organizations are urged to patch affected versions and treat mobile device management systems as high-value assets.
Key Takeaways
- CISA obtained malware exploiting Ivanti EPMM vulnerabilities CVE-2025-4427 and CVE-2025-4428.
- Malicious listeners in loaders allow arbitrary code execution on compromised servers.
- Organizations should patch Ivanti EPMM and treat MDM systems as high-value assets.