← Back to Feed

Malicious Listener for Ivanti Endpoint Mobile Management Systems

CVE-2025-4427CVE-2025-4428

September 17, 2025 · CISA Advisories · Severity: HIGH

CISA obtained malware from organizations compromised via Ivanti EPMM vulnerabilities CVE-2025-4427 and CVE-2025-4428, revealing loaders for malicious listeners enabling arbitrary code execution.

Key Takeaways

  • Threat actors exploit CVE-2025-4427 and CVE-2025-4428 in Ivanti EPMM to deploy malicious listeners
  • The malicious listeners enable arbitrary code execution on compromised Ivanti servers
  • Organizations should upgrade Ivanti EPMM to patched versions immediately
☕ Buy a Coffee