Skip to content
Ivanti Endpoint Manager: Attackers can write data to hard drive

Ivanti Endpoint Manager: Attackers can write data to hard drive

Heise.De • November 13, 2025

Attackers can exploit a software vulnerability in Ivanti Endpoint Manager (EPM). A security patch is available.

With EPM, administrators manage computers in companies. This makes it a lucrative target for a cyberattack. The vulnerability listed in a security advisory (CVE-2025-9713 " high ") enables attackers to write files to the hard drives of victim PCs. How this could happen in detail is currently unclear. The developers assure that there are currently no indications of attacks.

According to their own statements, they have closed the vulnerability in EPM 2024 SU4 . In a security advisory, the developers point out that support for the EPM version branch 2022 expired in October of this year. The version is now no longer receiving security updates and therefore poses a risk. Administrators should upgrade to a still-supported version promptly.

This article was originally published in German . It was translated with technical assistance and editorially reviewed before publication.

Extracted Entities