Ivanti

Ivanti warns of new Connect Secure flaw used in zero-day attacks

Share:

Ivanti is warning that hackers exploited a Connect Secure remote code execution vulnerability tracked as CVE-2025-0282 in zero-day attacks to install malware on appliances.

The company says it became aware of the vulnerabilities after the Ivanti Integrity Checker Tool (ICT) detected malicious activity on customers’ appliances. Ivanti launched an investigation and confirmed that threat actors were actively exploiting CVE-2025-0282 as a zero-day.

CVE-2025-0282 is a critical (9.0) stack-based buffer overflow bug in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7R1.2, and Ivanti Neurons for ZTA gateways before version 22.7R2.3 that allows a unauthenticated attacker to remotely execute code on devices.

While the flaw impacts all three products, Ivanti says they have only seen it exploited on Ivanti Connect Secure appliances.

“We are aware of a limited number of customers’ Ivanti Connect Secure appliances which have been exploited by CVE-2025-0282 at the time of disclosure,” reads an Ivanti blog post.

“We are not aware of these CVEs being exploited in Ivanti Policy Secure or Neurons for ZTA gateways.”

Ivanti has rushed out security patches for Ivanti Connect Secure, which are resolved in firmware version 22.7R2.5.

However, patches for Ivanti Policy Secure and Ivanti Neurons for ZTA Gateways will not be ready until January 21, according to a security bulletin published today.

Ivanti Policy Secure: This solution is not intended to be internet facing, which makes the risk of exploitation significantly lower. The fix for Ivanti Policy Secure is planned for release on January 21, 2025, and will be available in the standard download portal. Customers should always ensure that their IPS appliance is configured according to Ivanti recommendations and not expose it to the internet. We are not aware of these CVEs being exploited in Ivanti Policy Secure.

Ivanti Neurons for ZTA Gateways: The Ivanti Neurons ZTA gateways cannot be exploited when in production. If a gateway for this solution is generated and left unconnected to a ZTA controller, then there is a risk of exploitation on the generated gateway. The fix is planned for release on January 21, 2025. We are not aware of these CVEs being exploited in ZTA Gateways.

The company recommends all Ivanti Connect Secure admins perform internal and external ICT scans.

If the scans come up clean, Ivanti still recommends admins perform a factory reset before upgrading to Ivanti Connect Secure 22.7R2.5.

However, if the scans show signs of a compromise, Ivanti says a factory reset should remove any installed malware. The appliance should then be put back into production using version 22.7R2.5

Today’s security updates also fix a second vulnerability tracked as CVE-2025-0283, which Ivanti says is not currently being exploited or chained with CVE-2025-0282. This flaw allows an authenticated local attacker to escalate their privileges.

As Ivanti is working with Mandiant and the Microsoft Threat Intelligence Center to investigate the attacks, we will likely see reports about the detected malware shortly.

BleepingComputer contacted Ivanti with further questions about the attacks and will update this story if we receive a response.

In October, Ivanti released security updates to fix three Cloud Services Appliance (CSA) zero-days that were actively exploited in attacks.

Source

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
1:13 am, Jun 8, 2025
weather icon 10°C
L: 9° | H: 11°
broken clouds
Humidity: 91 %
Pressure: 1009 mb
Wind: 6 mph NW
Wind Gust: 10 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 52%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 4:44 am
Sunset: 9:14 pm
DailyHourly
Daily ForecastHourly Forecast
Today 10:00 pm
weather icon
9° | 11°°C 0.5 mm 50% 12 mph 90 % 1021 mb 0 mm/h
Tomorrow 10:00 pm
weather icon
10° | 19°°C 0.03 mm 3% 9 mph 87 % 1022 mb 0 mm/h
Tue Jun 10 10:00 pm
weather icon
13° | 21°°C 0.33 mm 33% 9 mph 85 % 1020 mb 0 mm/h
Wed Jun 11 10:00 pm
weather icon
13° | 25°°C 0 mm 0% 9 mph 92 % 1020 mb 0 mm/h
Thu Jun 12 10:00 pm
weather icon
18° | 26°°C 1 mm 100% 13 mph 93 % 1012 mb 0 mm/h
Today 4:00 am
weather icon
9° | 10°°C 0 mm 0% 10 mph 90 % 1010 mb 0 mm/h
Today 7:00 am
weather icon
10° | 11°°C 0 mm 0% 10 mph 81 % 1013 mb 0 mm/h
Today 10:00 am
weather icon
14° | 14°°C 0 mm 0% 12 mph 53 % 1017 mb 0 mm/h
Today 1:00 pm
weather icon
18° | 18°°C 0 mm 0% 12 mph 44 % 1019 mb 0 mm/h
Today 4:00 pm
weather icon
16° | 16°°C 0 mm 0% 9 mph 51 % 1019 mb 0 mm/h
Today 7:00 pm
weather icon
15° | 15°°C 0.48 mm 48% 10 mph 74 % 1019 mb 0 mm/h
Today 10:00 pm
weather icon
13° | 13°°C 0.5 mm 50% 8 mph 80 % 1021 mb 0 mm/h
Tomorrow 1:00 am
weather icon
11° | 11°°C 0.03 mm 3% 7 mph 81 % 1022 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€92,650.37
1.21%
Ethereum(ETH)
€2,214.90
1.87%
Tether(USDT)
€0.88
-0.02%
XRP(XRP)
€1.91
0.71%
Solana(SOL)
€131.58
1.41%
USDC(USDC)
€0.88
0.00%
Dogecoin(DOGE)
€0.162276
3.32%
Shiba Inu(SHIB)
€0.000011
2.34%
Pepe(PEPE)
€0.000011
3.90%
Peanut the Squirrel(PNUT)
€0.234364
7.64%
Scroll to Top