None
EN
CISA Warns of Two Malware Strains Exploiting Ivanti EPMM CVE-2025-4427 and CVE-2025-4428
['The Hacker News', 'Sep', 'Ravie Lakshmanan']
The Hacker News
"Each set contains loaders for malicious listeners that enable cyber threat actors to run arbitrary code on the compromised server," CISA said in an alert.
While CVE-2025-4427 concerns an authentication bypass that allows attackers to access protected resources, CVE-2025-4428 enables remote code execution.
As a result, the two flaws could be chained to execute arbitrary code on a vulnerable device without authentication.
According to CISA, the threat actors gained access to server running EPMM by combing the two vulnerabilities around May 15, 2025, following the publication of a proof-of-concept (PoC) exploit.
The end result is that it allows the attackers to inject and execute arbitrary code on the server, enabling follow-on activity and persistence, as well as exfiltrate data by intercepting and processing HTTP requests.
['cisa'
'sets'
'execute'
'code'
'exploiting'
'ivanti'
'warns'
'cve20254428'
'threat'
'access'
'strains'
'loader'
'webinstalljar'
'cve20254427'
'arbitrary'
'malicious'
'epmm'
'malware']