Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
HighCISA KEVExploited in the wildPublic exploit

Ivanti EPMM Path Traversal / Remote Arbitrary File Write

IdentifiersCVE-2023-35081CWE-22· Improper Limitation of a Pathname…

CVE-2023-35081 is a path traversal vulnerability in Ivanti Endpoint Manager Mobile (EPMM), formerly MobileIron Core. It affects supported versions 11.10.x prior to 11.10.0.3, 11.9.x prior to 11.9.1.2, and 11.8.x prior to 11.8.1.2. The flaw allows an authenticated EPMM administrator to write arbitrary files onto the appliance. Reporting and vendor statements describe this as a directory traversal/arbitrary file write issue that can be used to place attacker-controlled files, including webshells, with the operating system privileges of the EPMM web application server. Multiple sources in the provided content note that this vulnerability was observed being chained with CVE-2023-35078, which can bypass administrator authentication and ACL restrictions, thereby turning the nominal authenticated-admin requirement into a practical remote exploitation path in real-world attacks.

Share:
For your environment

Are you exposed to this one?

Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.

ANALYST BRIEF

Impact, mitigation & remediation

What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.

Impact

What an attacker gets, and what they’ve been doing with it.

Successful exploitation allows arbitrary file overwrite/write on the EPMM appliance. This can enable deployment of webshells, persistence, modification of application or system files, and potentially operating-system command execution in the security context of the EPMM web application server (described in the content as the tomcat user / web application server OS privileges). In observed campaigns, the flaw was used in conjunction with CVE-2023-35078 against government targets, materially increasing the risk from authenticated file write to full server compromise and follow-on intrusion activity.

Mitigation

If you can’t patch tonight, do this now.

If immediate patching is not possible, reduce exposure of the EPMM appliance, restrict administrative access as tightly as possible, and monitor for suspicious file creation or modification on the appliance. Hunt for indicators of webshell deployment and anomalous access to EPMM administrative/API paths, particularly where CVE-2023-35078 may have enabled unauthorized admin-level access. Given the documented chaining with CVE-2023-35078, mitigation should also include urgent remediation of related EPMM flaws and treating the appliance as potentially compromised until validated otherwise.

Remediation

Patch, then assume compromise.

Upgrade Ivanti EPMM to a fixed supported release: 11.10.0.3, 11.9.1.2, or 11.8.1.2, as applicable. Ivanti released the patch for CVE-2023-35081 on 2023-07-28. Because the vulnerability has been actively exploited, remediation should include not only patching but also investigation for prior compromise, especially if the appliance was internet-exposed or if CVE-2023-35078 may also have been present. If compromise is suspected, review for unauthorized files/webshells, assess configuration changes, rotate relevant credentials, and rebuild or restore from known-good media/backups as appropriate.
PUBLIC EXPLOITS

Exploits

No public exploits tracked yet. Mallory keeps watching.

VALID 0 / 0 TOTALView more in app

No public exploit code observed for this vulnerability.

EXPOSURE SURFACE

Affected products & vendors

Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.

VendorProductType
IvantiEndpoint Manager Mobileapplication

Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets are affected, which adversaries are exploiting it right now, which detections to deploy, and what to do tonight.
Exposure mapping

Query your assets running an affected version, and investigate the blast radius.

Threat actor evidence1

Every observed campaign linking this CVE to a named adversary.

Associated malware

Malware families riding this exploit, with evidence and IOCs.

Detection signatures2

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Vendor-by-vendor mapping

Cross-references every affected SKU, including bundled OEM variants.

Social activity

Community discussion across Reddit, Mastodon, and other social sources.