HomeSecurityCISA: Two malware exploits Ivanti EPMM vulnerabilities

CISA: Two malware exploits Ivanti EPMM vulnerabilities

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has released details of two sets of malware discovered on the network of an unnamed organization, after exploiting security vulnerabilities in Ivanti Endpoint Manager Mobile (Ivanti EPMM).

Ivanti EPMM CISA vulnerabilities

“ Each set contains loaders for malicious listeners that allow cybercriminals to execute arbitrary code on the compromised server ,” CISA said in an alert

The vulnerabilities used in the attack include CVE-2025-4427 and CVE-2025-4428, which were used as zero-days before being patched by Ivanti in May 2025.

CVE-2025-4427 concerns an authentication bypass that allows attackers to gain access to protected resources, while CVE-2025-4428 allows remote code execution. The two vulnerabilities can be combined to execute arbitrary code on a vulnerable device without authentication.

See also: WatchGuard fixes critical VPN flaw in firewalls

Ivanti EPMM: Server Breach

According to CISA, around May 15, 2025, attackers gained access to a server running EPMM. They exploited both vulnerabilities after publishing a proof-of-concept (PoC) exploit. The attackers were able to execute commands that allowed them to collect system information , download malicious files , capture the root directory , map the network , run scripts to create a heapdump, and extract Lightweight Directory Access Protocol (LDAP) credentials

CISA: Two malware exploits Ivanti EPMM vulnerabilities

Further analysis showed that the cybercriminals deposited two sets of malicious files in the “/tmp” directory, each of which allows persistence by inserting and executing arbitrary code on the compromised server:

  • Set 1 – web-install.jar (also known as Loader 1), ReflectUtil.class, and SecurityHandlerWanListener.class
  • Set 2 – web-install.jar (also known as Loader 2) and WebAndroidAppInstaller.class

Both sets contain a loader that launches a malicious compiled Java class listener, which intercepts specific HTTP requests and processes them to decode and decrypt payloads for subsequent execution.

See also: Critical vulnerability in Microsoft Entra ID allows full administrative control

“The ReflectUtil.class manipulates Java objects to import and manage the malicious SecurityHandlerWanListener listener in Apache Tomcat,” CISA said. “[The SecurityHandlerWanListener.class] is a malicious listener that intercepts specific HTTP requests and processes them to decode and decrypt payloads, which dynamically create and execute a new class.”

The WebAndroidAppInstaller.class retrieves and decrypts a password parameter from the request using a hard-coded key, which is used to define and implement a new class. The execution of the new class is then encrypted using the same hard-coded key and generates a response with the encrypted output.

The end result is that it allows attackers to inject and execute arbitrary code on the server, enabling subsequent activity and persistence, as well as data extraction by intercepting and processing HTTP requests.

To stay protected from these attacks, organizations are urged to update Ivanti EPMM to the latest version, monitor for signs of suspicious activity , and implement necessary restrictions to prevent unauthorized access to mobile device management (MDM) systems.

See also: TP-Link Routers: PoC exploit for zero-day released

CISA: Two malware exploits Ivanti EPMM vulnerabilities

Overall, the situation shows that timely patching is not an option but a necessity. At the same time, monitoring for suspicious network movements and implementing segmentations can act as a “safety net” when traditional defenses fail. In a world where MDM systems are the “heart” of mobile work, any weakness in them translates into a potentially catastrophic breach.

CISA’s recent warning once again highlights the growing risk of zero-day vulnerabilities in critical mobile device management platforms , such as Ivanti EPMM . The incident is not just an isolated breach; it reflects the strategic targeting of software that is a central access point to corporate networks by attackers. The ability to inject arbitrary code and maintain persistence reveals how quickly a technical PoC exploit can turn into a real threat.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS