Executive brief
Ivanti Pulse Connect Secure contains a use-after-free and authentication bypass vulnerability in the Windows File Share Browser and Pulse Secure Collaboration features. A remote, unauthenticated attacker can exploit this to execute arbitrary code on the gateway. This vulnerability has been observed being exploited in the wild.
Affected products
- Ivanti Pulse Connect Secure 9.0R3 and higher; 9.1R1 and higher
Timeline
- 2021-04-20: disclosed: Initial discovery/reporting of zero-day exploitation by FireEye/Mandiant
- 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2021-11-03: advisory: NVD publication date