CVE-2025-13659

Publication date

2025-12-09 15:59:18

Family

ivanti

State

PUBLISHED

Description

Improper control of dynamically managed code resources in Ivanti Endpoint Manager prior to version 2024 SU4 SR1 allows a remote, unauthenticated attacker to write arbitrary files on the server, potentially leading to remote code execution. User interaction is required.