Ivanti warns hackers are exploiting new vulnerability
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-0282 | Unauthenticated RCE in Ivanti Connect Secure, Policy Secure, and ZTA Gateways CVE-2025-0282 is a stack-based buffer overflow (CWE-121) in Ivanti Connect Secure, Policy Secure, and ZTA Gateways, reachable by unauthenticated network input. An attacker can trigger it remotely by sending crafted, unauthenticated traffic to a vulnerable gateway, overwriting stack memory and gaining code execution under the appliance's context. Successful exploitation yields unauthenticated remote code execution on the device, giving the attacker control of the VPN/secure-access gateway and a foothold into the protected network. Organizations running any of the affected Ivanti secure-access products are exposed; the source data specifies no version ranges, so defenders should consult Ivanti's advisory for exact affected and fixed releases. The flaw is being actively exploited: it was added to CISA KEV on 2025-01-08 with known ransomware use, and EPSS assigns a 100% probability of exploitation within 30 days (100th percentile), despite no public PoC being known. Do: Apply the patched releases identified in Ivanti's advisory and follow CISA's required action: hunt for signs of compromise, remediate if indicators are found, and apply updates before returning any device to service. Because exploitation is active and ransomware use is known, treat any appliance that was internet-reachable before patching as potentially compromised (check integrity, rotate credentials). Exact fixed versions were not included in the source data, so verify the correct update path for your branch (including older Connect Secure/Policy Secure releases) against Ivanti's bulletin. | 9.0 | 100% | KEV ransomware PoC ×3 |
| largetens of thousands of internet-exposed appliances (likely 100,000+ total deployments including internal-only gateways) | |
| CVE-2025-0283 | A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7R1.2, and Ivanti Neurons for ZTA gateway A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7R1.2, and Ivanti Neurons for ZTA gateways before version 22.7R2.3 allows a local authenticated attacker to escalate their privileges. NVD description · AI analysis pending | 7.0 | 17% |
| — |
Full article528 words · extracted from therecord.media · click to collapse
IT software vendor Ivanti said Wednesday that multiple customers have been affected by a new vulnerability being exploited by hackers. The company released an advisory and a corresponding blog about two bugs — CVE-2025-0282 and CVE-2025-0283 — and warned that some customers have already seen CVE-2025-0282 exploited in their environments. The bugs affect the company’s Connect Secure, Policy Secure and ZTA Gateways products — all of which are used widely across local and federal government agencies in the U.S. as well as internationally. “We are aware of a limited number of customers’ Ivanti Connect Secure appliances which have been exploited by CVE-2025-0282 at the time of disclosure. We are not aware of these CVEs being exploited in Ivanti Policy Secure or Neurons for ZTA gateways,” Ivanti said in a statement, adding that it has not seen exploitation of CVE-2025-0283. Ivanti said a patch is currently available for Connect Secure but patches for Policy Secure and ZTA Gateway are slated for release on January 21. The U.K.’s National Cyber Security Centre (NCSC) published its own advisory warning of “active exploitation.” “The NCSC is working to fully understand the UK impact and investigating cases of active exploitation affecting UK networks,” the agency said. Customers can see if they have been attacked through an Integrity Checker Tool (ICT), and can safely upgrade to the latest version of the software if they find no evidence of exploitation. If exploitation is found customers should perform a factory reset on the appliance to ensure any malware is removed, Ivanti said. The company urged customers not to expose any of their devices to the internet, something federal cybersecurity agencies have also previously warned organizations against. “We continue to work closely with affected customers, external security partners, and law enforcement agencies as we respond to this threat,” the company said. “This incident serves as a reminder of the importance of continuous monitoring and proactive and layered security measures, particularly for edge devices (such as VPNs) which provide an essential service as the initial access point to a corporate network – but which are also highly appealing to attackers.” Ivanti said it will provide more information about the threat actor activity to customers that have confirmed impact. Last April, the company pledged a security overhaul after a cascade of headline-grabbing nation-state attacks broke through the systems of government agencies in the U.S. and Europe using vulnerabilities in Ivanti products. By September, the top cyber watchdogs in the U.S. urged federal agencies to either remove or upgrade certain Ivanti appliances that are no longer being updated and that were previously exploited in attacks. Correction: A previous version of this article said the bugs were discovered by Mandiant and Microsoft. Ivanti said its acknowledgement of Mandiant and Microsoft in the advisory was due to consultations that took place after the company had already discovered vulnerabilities.
No previous article
No new articles
Jonathan Greig
is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.
Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/ivanti-warns-of-hackers-exploiting-new-vulnerability