A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.6, Ivanti Policy Secure before version 22.7R1.4, and Ivanti ZTA Gateways before version 22.8R2.2 allows a remote unauthenticated attacker to achieve remote code execution.
The flaw consists of a stack-based buffer overflow in the components of Ivanti Connect Secure, Policy Secure and ZTA Gateways. An attacker sends a specially crafted network request without the need for authentication, which causes the allocated stack buffer to be exceeded and critical process control data to be overwritten. As a result, it is possible to hijack control of the code execution flow and execute arbitrary instructions in the context of the vulnerable service.
A remote, unauthenticated attacker can gain full remote code execution (RCE) on the vulnerable device, which in practice means the possibility of complete system takeover, theft of authentication credentials, establishment of a backdoor, and further lateral movement in the victim's network.
Products must be updated immediately to the following versions: Ivanti Connect Secure to version 22.7R2.6 or later, Ivanti Policy Secure to version 22.7R1.4 or later, Ivanti ZTA Gateways to version 22.8R2.2 or later. Details are available in the vendor's bulletin from April 2025.
Ivanti Connect Secure before version 22.7R2.6, Ivanti Policy Secure before version 22.7R1.4, Ivanti ZTA Gateways before version 22.8R2.2
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:HIvanti Connect Secure
APPIvanti22.7< 22.7Ivanti Policy Secure
APPIvanti22.7< 22.7Ivanti Zero Trust Access Gateway
APPIvanti22.8< 22.8
CISA KEV — detailsi
- Vendori
- Ivanti ↗
- Producti
- Connect Secure, Policy Secure, and ZTA Gateways
- Added to KEVi
- April 4, 2025
- Remediation deadline (US Federal)i
- April 11, 2025(overdue)
- Ransomwarei
- Active ransomware campaigns exploit this vulnerability
Apply mitigations as set forth in the CISA instructions linked below.
Ivanti Connect Secure, Policy Secure, and ZTA Gateways contains a stack-based buffer overflow vulnerability that allows a remote unauthenticated attacker to achieve remote code execution.
Related vulnerabilities
Stack-based buffer overflow RCE w Ivanti Connect Secure, Policy Secure i Neurons for ZTA
Command injection w Ivanti Connect Secure i Policy Secure — RCE jako administrator
Ivanti/Pulse Connect Secure — krytyczny auth bypass umożliwiający RCE
Krytyczny path traversal w Pulse Connect Secure — odczyt dowolnych plików bez uwierzytelnienia
Code injection w Ivanti Connect Secure i Policy Secure — RCE