ZeroHour
Help Net Securitypublished ()ingested @zeljkazorz

Ivanti Connect Secure zero-day exploited by attackers (CVE-2025-0282)

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-0282
Unauthenticated RCE in Ivanti Connect Secure, Policy Secure, and ZTA Gateways

CVE-2025-0282 is a stack-based buffer overflow (CWE-121) in Ivanti Connect Secure, Policy Secure, and ZTA Gateways, reachable by unauthenticated network input. An attacker can trigger it remotely by sending crafted, unauthenticated traffic to a vulnerable gateway, overwriting stack memory and gaining code execution under the appliance's context. Successful exploitation yields unauthenticated remote code execution on the device, giving the attacker control of the VPN/secure-access gateway and a foothold into the protected network. Organizations running any of the affected Ivanti secure-access products are exposed; the source data specifies no version ranges, so defenders should consult Ivanti's advisory for exact affected and fixed releases. The flaw is being actively exploited: it was added to CISA KEV on 2025-01-08 with known ransomware use, and EPSS assigns a 100% probability of exploitation within 30 days (100th percentile), despite no public PoC being known.

Do: Apply the patched releases identified in Ivanti's advisory and follow CISA's required action: hunt for signs of compromise, remediate if indicators are found, and apply updates before returning any device to service. Because exploitation is active and ransomware use is known, treat any appliance that was internet-reachable before patching as potentially compromised (check integrity, rotate credentials). Exact fixed versions were not included in the source data, so verify the correct update path for your branch (including older Connect Secure/Policy Secure releases) against Ivanti's bulletin.

9.0100% KEV ransomware PoC ×3
  • Ivanti Connect Secure
  • Ivanti Policy Secure
  • Ivanti ZTA Gateways
largetens of thousands of internet-exposed appliances (likely 100,000+ total deployments including internal-only gateways)
CVE-2025-0283
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7R1.2, and Ivanti Neurons for ZTA gateway

A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7R1.2, and Ivanti Neurons for ZTA gateways before version 22.7R2.3 allows a local authenticated attacker to escalate their privileges.

NVD description · AI analysis pending
7.017%
  • ivanti connect secure
  • ivanti neurons for zero-trust access
  • ivanti policy secure
Full article412 words · extracted from helpnetsecurity.com · click to collapse

NEW STORY: Thursday, January 9, 07:30 ET
Ivanti Connect Secure zero-day exploited since mid-December (CVE-2025-0282)

Ivanti has fixed two vulnerabilities affecting Ivanti Connect Secure, Policy Secure and ZTA gateways, one of which (CVE-2025-0282) has been exploited as a zero-day by attackers to compromise Connect Secure VPN appliances.

Ivanti exploited zero-day CVE-2025-0282

About CVE-2025-0282 and CVE-2025-0283

Both are stack-based buffer overflow issues: CVE-2025-0282 allows for unauthenticated remote code execution, CVE-2025-0283 can be used by a local authenticated attacker to escalate their privileges.

Ivanti says that a “limited number “of customers’ Ivanti Connect Secure appliances have been exploited due to CVE-2025-0282.

“Threat actor activity was identified by the Integrity Checker Tool (ICT) on the same day it occurred, enabling Ivanti to respond promptly and rapidly develop a fix,” the company noted.

“We are not aware of these CVEs being exploited in Ivanti Policy Secure or ZTA gateways. We have no indication that CVE-2025-0283 is being exploited or chained with CVE-2025-0282. As we were conducting our threat hunting, we also discovered the vulnerability being disclosed as CVE-2025-0283 and included it in the patch as well.”

Google’s Mandiant and Microsoft’s Threat Intelligence Center have helped Ivanti respond to this threat, so we can probably expect more information about the attack campaign(s) to be released soon.

Zero-days in a variety of Ivanti solutions – including Connect Secure – have been exploited by attackers throughout 2024.

What to do?

For the moment, patches are only available for supported versions of Ivanti Connect Secure; those for Policy Secure and Ivanti Neurons for ZTA gateways are in the works, and will be available on January 21.

The company asks customers to use both the internal and external Ivanti Connect Secure integrity checker tool (ICT) to verify whether the image installed on their Connect Secure appliances has been modified, while acknowledging at the same time that the ICT scan “cannot necessarily detect threat actor activity if they have returned the appliance to a clean state.”

If the scan reports changes, Ivanti advises:

  • Performing a factory reset on the appliance to ensure any malware is removed
  • Putting the appliance back into production using the version with the fix (v22.7R2.5)

Ivanti says it will share indicators of compromise with customers that have confirmed impact, so they can use them for forensics investigation. Additional information can be had by opening a ticket with support.

Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2025/01/08/ivanti-exploited-connect-secure-zero-day-cve-2025-0282-cve-2025-0283/