logo

MobileIrony backdoor allows complete takeover of mobile security product and endpoints.

ID: b41825a1-0dad-5095-8436-f24823174b40

STIX ID: report--b41825a1-0dad-5095-8436-f24823174b40

Feed Name: DoublePulsar

Threat Score
90/100

Date Published: 2023-07-25

Date Updated: 2026-04-19

Author: Kevin Beaumont

...
...

**Executive summary:** The report describes a critical unauthenticated API flaw (CVE-2023-35078, "MobileIrony") in Ivanti MobileIron/EPMM that allows any remote actor to perform administrative API actions (including creating admin accounts, querying LDAP, enumerating users and devices, deploying software, locking/wiping devices) without credentials; it has been exploited in the wild against government targets and warrants immediate patching and urgent customer notification.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.