Skip to content
CC-4726

CC-4726

Digital.Nhs.Uk [email protected] (NHS Digital) December 10, 2025

1 critical and 3 high severity vulnerabilities could allow a remote unauthenticated attacker to perform remote code execution in the context of an administrator session.

1 critical and 3 high severity vulnerabilities could allow a remote unauthenticated attacker to perform remote code execution in the context of an administrator session.

The following platforms are known to be affected:

Ivanti Endpoint Manager

Proof-of-Concept Exploit for CVE-2025-10573

Security researchers have published a proof-of-concept exploit for CVE-2025-10573.

The NHS England National CSOC assesses future exploitation as likely.

Ivanti has released security updates to address one critical severity and three high severity vulnerabilities in Ivanti EPM (Endpoint Manager).

Affected organisations are encouraged to review Ivanti's Security Advisory EPM December 2025 for EPM 2024 and apply the relevant update.

Stored XSS in Ivanti Endpoint Manager prior to version 2024 SU4 SR1 allows a remote unauthenticated attacker to execute arbitrary JavaScript in the context of an administrator session. User interaction is required.

Improper control of dynamically managed code resources in Ivanti Endpoint Manager prior to version 2024 SU4 SR1 allows a remote, unauthenticated attacker to write arbitrary files on the server, potentially leading to remote code execution. User interaction is required.

Path traversal in Ivanti Endpoint Manager prior to version 2024 SU4 SR1 allows a remote authenticated attacker to write arbitrary files outside of the intended directory. User interaction is required.

Improper verification of cryptographic signatures in the patch management component of Ivanti Endpoint Manager prior to version 2024 SU4 SR1 allows a remote unauthenticated attacker to execute arbitrary code. User Interaction is required.

Last edited: 10 December 2025 1:42 pm

Extracted Entities

Attack Types (1)

Companies (1)

Vulnerabilities (2)