PT-2025-1027 · Ivanti · Ivanti Policy Secure+2
Published
2025-01-08
·
Updated
2026-04-14
·
CVE-2025-0283
CVSS v3.1
7.0
High
| Vector | AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Ivanti Connect Secure versions prior to 22.7R2.5
Ivanti Policy Secure versions prior to 22.7R1.2
Ivanti Neurons for ZTA gateways versions prior to 22.7R2.3
Description
A stack-based buffer overflow exists in Ivanti Connect Secure, Ivanti Policy Secure, and Ivanti Neurons for ZTA gateways. Successful exploitation of this issue allows a local authenticated attacker to escalate their privileges. The issue also allows a remote unauthenticated attacker to achieve remote code execution. The vulnerability enables attackers to gain administrator access, potentially allowing them to modify settings, passwords, and systems, and access sensitive information.
Recommendations
Ivanti Connect Secure versions prior to 22.7R2.5 should be updated to version 22.7R2.5 or later.
Ivanti Policy Secure versions prior to 22.7R1.2 should be updated to version 22.7R1.2 or later.
Ivanti Neurons for ZTA gateways versions prior to 22.7R2.3 should be updated to version 22.7R2.3 or later.
Fix
LPE
Stack Overflow
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ivanti Connect Secure
Ivanti Neurons For Zta Gateways
Ivanti Policy Secure