ZeroHour
The Recordpublished ()ingested 1

Chinese spies targeting new Ivanti vulnerability, Mandiant says

criticalVulnerability exploited in the wildimportance 60CVE-2025-0282CVE-2023-46805CVE-2024-21887

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-21887
+1 in the same advisory: …46805
Command Injection RCE in Ivanti Connect Secure and Policy Secure

Ivanti Connect Secure (formerly Pulse Connect Secure) and Ivanti Policy Secure appliances contain a command injection flaw (CWE-77) in their web components, triggered when an authenticated administrator sends crafted requests to the appliance. The bug can be chained with the separate authentication bypass CVE-2023-46805, allowing an unauthenticated attacker to achieve the same result. Successful exploitation lets an attacker execute arbitrary commands and code on the appliance, providing a foothold into the networks behind the VPN or network access control gateway. Any organization running these appliances, typically enterprises and government agencies often deployed directly on the internet perimeter, is affected. Exploitation is confirmed in the wild: the flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2024-01-10 with known ransomware use and EPSS assigns a 100% probability of exploitation within 30 days, although no public proof-of-concept is available.

Do: Apply Ivanti's mitigations or patched builds immediately per vendor instructions, addressing the chained authentication bypass CVE-2023-46805 at the same time, and discontinue or restrict use of any appliance for which mitigations are unavailable, especially if it is internet-facing. Because exploitation with ransomware use is known, assume compromise is possible: review appliance web logs for suspicious requests and run Ivanti's integrity-checking guidance to verify appliance images before and after remediation. Where feasible, restrict direct internet exposure of the appliance web interface and monitor for further vendor advisories.

9.1
group max
100% KEV ransomware PoC
  • Ivanti Connect Secure (ICS, formerly Pulse Connect Secure)
  • Ivanti Policy Secure
largetens of thousands of appliances (roughly 20,000-30,000 internet-exposed ICS gateways at disclosure; total deployed base likely higher)
CVE-2025-0282
Unauthenticated RCE in Ivanti Connect Secure, Policy Secure, and ZTA Gateways

CVE-2025-0282 is a stack-based buffer overflow (CWE-121) in Ivanti Connect Secure, Policy Secure, and ZTA Gateways, reachable by unauthenticated network input. An attacker can trigger it remotely by sending crafted, unauthenticated traffic to a vulnerable gateway, overwriting stack memory and gaining code execution under the appliance's context. Successful exploitation yields unauthenticated remote code execution on the device, giving the attacker control of the VPN/secure-access gateway and a foothold into the protected network. Organizations running any of the affected Ivanti secure-access products are exposed; the source data specifies no version ranges, so defenders should consult Ivanti's advisory for exact affected and fixed releases. The flaw is being actively exploited: it was added to CISA KEV on 2025-01-08 with known ransomware use, and EPSS assigns a 100% probability of exploitation within 30 days (100th percentile), despite no public PoC being known.

Do: Apply the patched releases identified in Ivanti's advisory and follow CISA's required action: hunt for signs of compromise, remediate if indicators are found, and apply updates before returning any device to service. Because exploitation is active and ransomware use is known, treat any appliance that was internet-reachable before patching as potentially compromised (check integrity, rotate credentials). Exact fixed versions were not included in the source data, so verify the correct update path for your branch (including older Connect Secure/Policy Secure releases) against Ivanti's bulletin.

9.0100% KEV ransomware PoC ×3
  • Ivanti Connect Secure
  • Ivanti Policy Secure
  • Ivanti ZTA Gateways
largetens of thousands of internet-exposed appliances (likely 100,000+ total deployments including internal-only gateways)
Full article813 words · extracted from therecord.media · click to collapse

A newly publicized vulnerability in popular products from tech company Ivanti is being exploited by China-based espionage threat actors, according to Google-owned cybersecurity firm Mandiant.

Mandiant published a blog post detailing its examination of CVE-2025-0282 — a vulnerability Ivanti announced on Wednesday that affects the company’s popular Connect Secure VPN appliance. 

On Wednesday night, the leading U.S. cybersecurity agency ordered all federal civilian agencies to patch the vulnerability by January 15 — the shortest time frame it has ever issued since creating its Known Exploited Vulnerabilities Catalog.

Experts at Mandiant attributed exploitation of the bug to China-based hackers because the malware seen in attacks has only ever been used by Chinese campaigns exploiting Ivanti Connect Secure appliances. 

Mandiant incident responders first saw exploitation of CVE-2025-0282 in the middle of December and are currently analyzing multiple compromised Ivanti Connect Secure appliances from multiple organizations.

While they have not tied all of the activity to one threat actor, one of the deployed malware families — which Mandiant names SPAWN — was only previously spotted during the compromise of Ivanti Connect Secure VPN appliances exactly one year ago by actors exploiting bugs tracked as CVE-2023-46805 and CVE-2024-21887. 

The hackers that exploited those vulnerabilities as early as December 2023 are part of a group Mandiant called UNC5221. 

“Mandiant assesses that defenders should be prepared for widespread, opportunistic exploitation, likely targeting credentials and the deployment of web shells to provide future access,” Wednesday’s blog post said. “Additionally, if proof-of-concept exploits for CVE-2025-0282 are created and released, Mandiant assesses it is likely additional threat actors may attempt targeting Ivanti Connect Secure appliances.”

Another cybersecurity firm, Volexity, previously attributed attacks involving CVE-2023-46805 and CVE-2024-21887 to Chinese nation-state-level threat actors. 

Since 2020, the Cybersecurity and Infrastructure Security Agency (CISA) has warned organizations repeatedly of state-backed hackers linked to China exploiting vulnerabilities in Ivanti products.

In April 2021, CISA warned that hackers breached the systems of a number of U.S. government agencies, critical infrastructure entities and other private sector organizations. Mandiant attributed the activity to hackers operating on behalf of the Chinese government.

The revelations come as U.S. officials contend with multiple China-focused hacking scandals. Treasury Secretary Janet Yellen said on Monday that she spoke directly with Chinese Vice Premier He Lifeng about the recent cyberattack on her office and the Office of Foreign Assets Control (OFAC). 

Bloomberg reported on Thursday that the attack on the Treasury Department was perpetrated by Chinese hackers that are part of the Silk Typhoon group. 

In addition to the Treasury Department incident, Biden administration officials are planning an array of executive orders and investigations designed to address the Salt Typhoon attacks that saw Chinese hackers break into nine major telecommunication giants and steal sensitive information on incoming President Donald Trump and other officials in his circle. 

Ivanti’s own tool

Mandiant’s investigation into attacks targeting CVE-2025-0282 also found several previously unobserved malware families named DRYHOOK and PHASEJAM that are currently not yet linked to a known group. 

Ivanti and several of its customers affected by the cyberattacks were able to identify compromises by using the company’s Integrity Checker Tool alongside other commercial security monitoring tools. 

“Ivanti’s Integrity Checker Tool (ICT) has been effective in identifying compromise related to this vulnerability,” a spokesperson for Ivanti told Recorded Future News on Thursday. 

“Threat actor activity was identified by the Integrity Checker Tool (ICT) on the same day it occurred, enabling Ivanti to respond promptly and rapidly develop a fix. We strongly advise customers to closely monitor their internal and external ICT as part of a robust and layered approach to cybersecurity to ensure the integrity and security of the entire network infrastructure.”

But Mandiant noted that in its investigations, the hackers attempted to circumvent the ICT scanner through a variety of tactics and tried to prevent legitimate attempts to upgrade devices. 

“Due to the blocked upgrade attempt, the technique would allow any installed backdoors or tools left by the threat actor to persist on the current running version of the VPN while giving the appearance of a successful upgrade,” Mandiant said, providing screenshots of what a successful ICT scan should look like versus an unsuccessful one on a compromised device. 

Ivanti notes in its own blog that the ICT is only a snapshot of the appliance and “cannot necessarily detect threat actor activity if they have returned the appliance to a clean state.” The ICT also does not scan for malware.

Mandiant said it saw the hackers trying to steal databases that may contain VPN sessions, session cookies, API keys, certificates, and credential material.

No previous article

No new articles

Jonathan Greig

is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.

Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/china-espionage-ivanti-vulnerabilities-mandiant