Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
widely-deployed-product-advisoryendpoint-software-vulnerabilityinternet-exposed-serviceinitial-access-method

Critical Remote Code Execution Vulnerability in Ivanti Endpoint Manager (CVE-2025-10573)

Updated 3mo agoFirst seen Dec 9, 20259 sources

Ivanti has disclosed a critical vulnerability (CVE-2025-10573) in its Endpoint Manager (EPM) software, which allows unauthenticated remote attackers to execute arbitrary JavaScript code via a stored cross-site scripting (XSS) attack. The flaw enables attackers to register fake managed endpoints to the EPM server, thereby injecting malicious JavaScript into the administrator web dashboard. When an administrator interacts with the compromised dashboard, the attacker can hijack the session and potentially gain full control over the EPM environment. Ivanti has released a patch (EPM 2024 SU4 SR1) to address this issue and strongly urges customers to update, especially since hundreds of EPM instances are exposed to the internet, increasing the risk of exploitation.

The vulnerability, assigned a CVSS score of 9.6, affects EPM versions 2024 SU4 and below. Security researchers at Rapid7, who discovered and reported the flaw, emphasize the urgency of patching due to the unauthenticated nature of the attack vector. Ivanti EPM is widely used for endpoint management, remote administration, and compliance, making it a high-value target for attackers. In addition to CVE-2025-10573, Ivanti has also released fixes for three other high-severity vulnerabilities in the same update cycle. Security teams are advised to apply the latest patches immediately and review the exposure of EPM instances to the internet to mitigate the risk of compromise.

Share:
Critical Remote Code Execution Vulnerability in Ivanti Endpoint Manager (CVE-2025-10573)
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

5 events from the most recent confirmed update back to the earliest known activity.

5 EVENTS
Dec 10, 20257mo ago

National cyber agencies issue follow-on advisories urging patching

On 2025-12-10, government cyber agencies including Canada's Cyber Centre and Singapore's CSA published advisories referencing Ivanti's December 9 security update and recommending that administrators review the vendor guidance and promptly apply the fixes. These notices reinforced the urgency of patching affected EPM deployments.

Dec 9, 20257mo ago

Technical details published for CVE-2025-10573 exploitation path

On 2025-12-09, Rapid7 and other reporting described how attackers could abuse the incomingdata web API and related CGI handler to submit malicious device scan data that is later rendered unsafely in the EPM dashboard. The write-up clarified that exploitation requires only that an administrator view the poisoned page, enabling attacker-controlled JavaScript execution.

Ivanti discloses critical CVE-2025-10573 in Endpoint Manager

On 2025-12-09, Ivanti publicly disclosed CVE-2025-10573, a critical unauthenticated stored XSS issue in Endpoint Manager that can let attackers poison the admin dashboard, execute JavaScript in administrator sessions, and hijack those sessions. The flaw affects versions prior to EPM 2024 SU4 SR1 and is especially risky for internet-exposed EPM instances.

Ivanti releases EPM 2024 SU4 SR1 to patch four vulnerabilities

On 2025-12-09, Ivanti released Endpoint Manager 2024 SU4 SR1 to fix the critical stored XSS flaw CVE-2025-10573 and three additional high-severity vulnerabilities affecting EPM 2024 SU4 and earlier. Ivanti said no active exploitation had been observed at the time of disclosure and urged customers to update immediately.

Researchers responsibly disclose Ivanti EPM vulnerabilities to Ivanti

Multiple vulnerabilities in Ivanti Endpoint Manager, including CVE-2025-10573, were responsibly disclosed to Ivanti by researchers from Rapid7, watchTowr, and Trend Zero Day Initiative. Rapid7 said the disclosure process for CVE-2025-10573 was coordinated with Ivanti and included extensions to allow a comprehensive fix.

The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

Critical Remote Code Execution Vulnerability in Ivanti Endpoint Manager (CVE-2025-10573) | Mallory