← Back to Feed

Malicious Listener for Ivanti Endpoint Mobile Management Systems

CVE-2025-4427CVE-2025-4428

September 17, 2025 · CISA Advisories · Severity: HIGH

CISA obtained two sets of malware from an organization compromised by threat actors exploiting vulnerabilities in Ivanti Endpoint Manager Mobile. The malware contains loaders for malicious listeners that enable arbitrary code execution on the compromised server. Organizations are urged to patch affected versions and treat mobile device management systems as high-value assets.

Key Takeaways

  • CISA obtained malware exploiting Ivanti EPMM vulnerabilities CVE-2025-4427 and CVE-2025-4428.
  • Malicious listeners in loaders allow arbitrary code execution on compromised servers.
  • Organizations should patch Ivanti EPMM and treat MDM systems as high-value assets.
☕ Buy a Coffee