Ivanti Connect Secure: Attackers attack critical vulnerability

Share:

Ivanti warns of active attacks on Ivanti Secure Connect systems. Code smuggling can compromise networks.

Ivanti warns of active attacks on a critical vulnerability in the VPN software Ivanti Connect Secure (ICS). These and another vulnerability also affect Ivanti Policy Secure and Ivanti ZTA Gateways. Updates are available for ICS, but Ivanti has only announced updates for the other two products.

In a security advisory, Ivanti discusses details about the vulnerabilities. The company has discovered attacks on a stack-based buffer overflow that allows the malicious actors to inject and execute malicious code without prior registration (CVE-2025-0282, CVSS 9.0, risk “critical“). Ivanti does not discuss exactly what the attacks look like. A second vulnerability also exists in a stack-based buffer overflow that allows logged-in users to escalate their own privileges (CVE-2025-0283, CVSS 7.0high). However, according to Ivanti, this vulnerability is not currently being abused.

Google’s subsidiary Mandiant presents an initial analysis of the attacks in its own blog post. The attackers installed malware from the ecosystem called Spawn by Mandiant after successful attacks, but also malware families called Dryhook and Phasejam. The exploits for the vulnerability are version-specific for the individual patch levels of ICS. The malware then ends up providing tunnels, web shells, preventing updates, tapping access data and can cause further damage. Mandiant locates the attackers UNC5337 as a subgroup of UNC5221 in China, so it is an espionage group.

Ivanti speaks of knowing of a limited number of attacked customers. Mandiant explains that the attacks began in mid-December 2024. The analyses are still ongoing, the results so far are still preliminary. At the end of the article, Mandiant lists Indicators Of Compromise (IOCs) as well as helpful YARA rules that admins can use to examine their IT and be warned of attacks.

Ivanti explains that attacks on the CVE-2025-0282 vulnerability can be detected with the Integrity Checker Tool (ICT). Customers should closely monitor their internal and external ICTs as part of their security concept. Updated software is also available. Ivanti Connect Secure 22.7R2.5 plugs the vulnerability in the vulnerable versions 22.7R2 to 22.7R.4 as well as 9.1R18.9 and previous versions. Ivanti Policy Secure is also vulnerable, but is not said to be exposed on the Internet. Ivanti ZTA Gateways are only vulnerable if they are not “in production”. However, if a gateway is created with it and not connected to the ZTA controller, an exploit is possible. A software patch is also to be available for this on January 21.

Source

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
1:53 pm, Mar 16, 2025
weather icon 9°C
L: 8° | H: 11°
broken clouds
Humidity: 55 %
Pressure: 1024 mb
Wind: 12 mph NNE
Wind Gust: 0 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 75%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 6:12 am
Sunset: 6:06 pm
DailyHourly
Daily ForecastHourly Forecast
Today 9:00 pm
weather icon
8° | 11°°C 0 mm 0% 11 mph 70 % 1026 mb 0 mm/h
Tomorrow 9:00 pm
weather icon
3° | 9°°C 0 mm 0% 10 mph 89 % 1029 mb 0 mm/h
Tue Mar 18 9:00 pm
weather icon
4° | 10°°C 0 mm 0% 12 mph 78 % 1027 mb 0 mm/h
Wed Mar 19 9:00 pm
weather icon
3° | 15°°C 0 mm 0% 7 mph 79 % 1022 mb 0 mm/h
Thu Mar 20 9:00 pm
weather icon
8° | 14°°C 0 mm 0% 7 mph 78 % 1021 mb 0 mm/h
Today 3:00 pm
weather icon
9° | 10°°C 0 mm 0% 11 mph 56 % 1024 mb 0 mm/h
Today 6:00 pm
weather icon
8° | 8°°C 0 mm 0% 8 mph 58 % 1024 mb 0 mm/h
Today 9:00 pm
weather icon
5° | 6°°C 0 mm 0% 3 mph 70 % 1026 mb 0 mm/h
Tomorrow 12:00 am
weather icon
5° | 5°°C 0 mm 0% 6 mph 84 % 1027 mb 0 mm/h
Tomorrow 3:00 am
weather icon
4° | 4°°C 0 mm 0% 7 mph 89 % 1027 mb 0 mm/h
Tomorrow 6:00 am
weather icon
3° | 3°°C 0 mm 0% 7 mph 81 % 1028 mb 0 mm/h
Tomorrow 9:00 am
weather icon
5° | 5°°C 0 mm 0% 7 mph 66 % 1029 mb 0 mm/h
Tomorrow 12:00 pm
weather icon
9° | 9°°C 0 mm 0% 8 mph 52 % 1028 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€75,746.85
-2.09%
Ethereum(ETH)
€1,723.66
-2.60%
Tether(USDT)
€0.92
-0.01%
XRP(XRP)
€2.10
-6.34%
Solana(SOL)
€117.68
-5.14%
USDC(USDC)
€0.92
0.00%
Dogecoin(DOGE)
€0.153157
-5.42%
Shiba Inu(SHIB)
€0.000012
-1.22%
Pepe(PEPE)
€0.000006
-6.21%
Peanut the Squirrel(PNUT)
€0.189019
20.47%
Scroll to Top