A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7R1.2, and Ivanti Neurons for ZTA gateways before version 22.7R2.3 allows a remote unauthenticated attacker to achieve remote code execution.
An attacker sends a specially crafted network request to the vulnerable device without needing any credentials. Exceeding the allowed data size written to the stack (stack-based buffer overflow, CWE-121, CWE-787) leads to overwriting memory areas beyond the intended buffer. This results in seizing control over the program execution flow and enables execution of arbitrary code (RCE) with the privileges of the process handling the connection.
An attacker can gain full control over the vulnerable device — execute arbitrary code, modify configuration, steal user credentials or use the compromised device as an entry point for further actions in the organization's network.
Products must be updated immediately to the following versions: Ivanti Connect Secure to version 22.7R2.5 or later, Ivanti Policy Secure to version 22.7R1.2 or later, Ivanti Neurons for ZTA gateways to version 22.7R2.3 or later. Detailed vulnerability mitigation instructions are available in Ivanti's official security advisory and CISA guidelines at the address indicated in the references.
Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7R1.2, Ivanti Neurons for ZTA gateways before version 22.7R2.3
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:HIvanti Connect Secure
APPIvanti22.7Ivanti Neurons For Zero Trust Access
APPIvanti22.7Ivanti Policy Secure
APPIvanti22.7
CISA KEV — detailsi
- Vendori
- Ivanti ↗
- Producti
- Connect Secure, Policy Secure, and ZTA Gateways
- Added to KEVi
- January 8, 2025
- Remediation deadline (US Federal)i
- January 15, 2025(overdue)
- Ransomwarei
- Active ransomware campaigns exploit this vulnerability
Apply mitigations as set forth in the CISA instructions linked below to include conducting hunt activities, taking remediation actions if applicable, and applying updates prior to returning a device to service.
Ivanti Connect Secure, Policy Secure, and ZTA Gateways contain a stack-based buffer overflow which can lead to unauthenticated remote code execution.
Related vulnerabilities
Stack-based buffer overflow w Ivanti Connect Secure, Policy Secure i ZTA Gateways umożliwiający RCE
Command injection w Ivanti Connect Secure i Policy Secure — RCE jako administrator
Ivanti/Pulse Connect Secure — krytyczny auth bypass umożliwiający RCE
Krytyczny path traversal w Pulse Connect Secure — odczyt dowolnych plików bez uwierzytelnienia
Code injection w Ivanti Connect Secure i Policy Secure — RCE