HTTP: Ivanti Endpoint Manager EFile CreateFile Directory Traversal
This signature detects attempts to exploit a known vulnerability against Ivanti. A successful attack can lead to directory traversal and arbitrary code execution.
Extended Description
Path traversal in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Updateallows a local unauthenticated attacker to achieve code execution. User interaction is required.
Affected Products
Ivanti endpoint_manager
References
CVE: CVE-2025-9872
URL: http://www.zerodayinitiative.com/advisories/ZDI-24-1501/ http://www.zerodayinitiative.com/advisories/ZDI-24-1505/ http://www.zerodayinitiative.com/advisories/ZDI-24-1503/ http://www.zerodayinitiative.com/advisories/ZDI-25-114/ http://www.zerodayinitiative.com/advisories/ZDI-25-952/
srx-branch-12.3
srx-19.3
srx-branch-19.3
vsrx3bsd-19.2
srx-branch-19.4
vsrx-19.4
mx-12.3
mx-19.4
vmx-19.4
mx-19.3
vsrx3bsd-19.4
srx-19.4
vsrx-12.3
vmx-19.3
vsrx-19.2
srx-12.3
Ivanti