ZeroHour
Infosecurity Magazinepublished ()ingested Phil Muncaster

Critical Ivanti Zero

criticalExploit / PoC exploited in the wildimportance 60CVE-2025-0282CVE-2025-0283

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-0282
Unauthenticated RCE in Ivanti Connect Secure, Policy Secure, and ZTA Gateways

CVE-2025-0282 is a stack-based buffer overflow (CWE-121) in Ivanti Connect Secure, Policy Secure, and ZTA Gateways, reachable by unauthenticated network input. An attacker can trigger it remotely by sending crafted, unauthenticated traffic to a vulnerable gateway, overwriting stack memory and gaining code execution under the appliance's context. Successful exploitation yields unauthenticated remote code execution on the device, giving the attacker control of the VPN/secure-access gateway and a foothold into the protected network. Organizations running any of the affected Ivanti secure-access products are exposed; the source data specifies no version ranges, so defenders should consult Ivanti's advisory for exact affected and fixed releases. The flaw is being actively exploited: it was added to CISA KEV on 2025-01-08 with known ransomware use, and EPSS assigns a 100% probability of exploitation within 30 days (100th percentile), despite no public PoC being known.

Do: Apply the patched releases identified in Ivanti's advisory and follow CISA's required action: hunt for signs of compromise, remediate if indicators are found, and apply updates before returning any device to service. Because exploitation is active and ransomware use is known, treat any appliance that was internet-reachable before patching as potentially compromised (check integrity, rotate credentials). Exact fixed versions were not included in the source data, so verify the correct update path for your branch (including older Connect Secure/Policy Secure releases) against Ivanti's bulletin.

9.0100% KEV ransomware PoC ×3
  • Ivanti Connect Secure
  • Ivanti Policy Secure
  • Ivanti ZTA Gateways
largetens of thousands of internet-exposed appliances (likely 100,000+ total deployments including internal-only gateways)
CVE-2025-0283
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7R1.2, and Ivanti Neurons for ZTA gateway

A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7R1.2, and Ivanti Neurons for ZTA gateways before version 22.7R2.3 allows a local authenticated attacker to escalate their privileges.

NVD description · AI analysis pending
7.017%
  • ivanti connect secure
  • ivanti neurons for zero-trust access
  • ivanti policy secure
Full article423 words · extracted from infosecurity-magazine.com · click to collapse

The UK’s National Cyber Security Centre (NCSC) and its US equivalent have urged Ivanti customers to take immediate action to mitigate two new vulnerabilities, one of which is being actively exploited.

Ivanti released a security advisory on Wednesday outlining the two stack-based buffer overflow flaws in its Ivanti Connect Secure, Policy Secure and ZTA gateways products.

CVE-2025-0282 is a critical zero-day vulnerability with a CVSS score of 9.0 that could lead to unauthenticated remote code execution (RCE), according to the security vendor. It affects Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7R1.2 and Ivanti Neurons for ZTA gateways before version 22.7R2.3.

The second vulnerability, CVE-2025-0283, could allow a local authenticated attacker to escalate privileges, Ivanti warned. It impacts Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7R1.2, and Ivanti Neurons for ZTA gateways before version 22.7R2.3.

The issues were discovered by researchers at Microsoft and Google Mandiant. The latter claimed it had observed zero-day exploitation of CVE-2025-0282 from mid-December 2024.

“We are aware of a limited number of customers’ Ivanti Connect Secure appliances being exploited by CVE-2025-0282 at the time of disclosure. We are not aware of these CVEs being exploited in Ivanti Policy Secure or ZTA gateways,” the Ivanti advisory noted.

“We are not aware of any exploitation of CVE-2025-0283 at the time of disclosure.”

Read more on Ivanti zero-days: Two Ivanti Zero-Days Actively Exploited in the Wild

Patches are available for both vulnerabilities, but only for the Ivanti Connect Secure product. Users of the other two affected solutions will have to wait until January 21 for a fix, but no in-the-wild exploitation of these products has currently been reported.

Both the NCSC and US Cybersecurity and Infrastructure Security Agency (CISA) offered the same advice, as per Ivanti’s recommendations:

  • Run Ivanti’s Integrity Checker Tool (ICT) to detect exploitation of CVE-2025-0282
  • If compromised, report immediately to the NCSC/CISA
  • Perform a factory reset and install the latest security update for Ivanti Connect Secure
  • Ensure the Ivanti Policy Secure appliance is configured correctly and not exposed to the internet
  • Ivanti Neurons ZTA gateways can’t be exploited when in production. However, if a gateway is generated and left unconnected to a ZTA controller, there’s a risk of exploitation on the gateway
  • Perform continuous monitoring and threat hunting

“The NCSC is working to fully understand the UK impact and investigating cases of active exploitation affecting UK networks,” the agency said.

Almost a year ago, a high-severity authentication bypass vulnerability was discovered in Ivanti Connect Secure, Policy Secure and ZTA gateways.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/critical-ivanti-zeroday-exploited/