HTTP: Ivanti Endpoint Manager EFile CreateFile Directory Traversal
This signature detects attempts to exploit a known vulnerability against Ivanti. A successful attack can lead to directory traversal and arbitrary code execution.
Extended Description
Path traversal in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Updateallows a local unauthenticated attacker to achieve code execution. User interaction is required.
Affected Products
Ivanti endpoint_manager
References
CVE: CVE-2025-9872
URL: http://www.zerodayinitiative.com/advisories/ZDI-24-1501/ http://www.zerodayinitiative.com/advisories/ZDI-24-1505/ http://www.zerodayinitiative.com/advisories/ZDI-24-1503/ http://www.zerodayinitiative.com/advisories/ZDI-25-114/ http://www.zerodayinitiative.com/advisories/ZDI-25-952/
mx-19.3
vmx-19.3
vsrx-19.2
srx-19.3
srx-branch-19.3
vsrx3bsd-19.2
srx-19.4
vsrx3bsd-19.4
srx-branch-19.4
vsrx-19.4
vmx-19.4
mx-19.4
srxevo-25.4
vsrx-26.2
srx-26.2
srx-branch-26.2
vsrx3bsd-26.2
mx-12.3
srx-12.3
srx-branch-12.3
vsrx-12.3
Ivanti