← Back to Feed
Malicious Listener for Ivanti Endpoint Mobile Management Systems
CVE-2025-4427CVE-2025-4428
September 17, 2025 · CISA Advisories · Severity: HIGH
CISA obtained malware from organizations compromised via Ivanti EPMM vulnerabilities CVE-2025-4427 and CVE-2025-4428, revealing loaders for malicious listeners enabling arbitrary code execution.
Key Takeaways
- Threat actors exploit CVE-2025-4427 and CVE-2025-4428 in Ivanti EPMM to deploy malicious listeners
- The malicious listeners enable arbitrary code execution on compromised Ivanti servers
- Organizations should upgrade Ivanti EPMM to patched versions immediately