Junglewise Threat Intelligence

CVE-2021-22893: Ivanti Pulse Connect Secure Use-After-Free Vulnerability

CVE-2021-22893 · Severity: critical · CVSS 10 · Exploited in the wild · Published 2021-11-03

Vendors: Ivanti.

Executive brief

Ivanti Pulse Connect Secure contains a use-after-free and authentication bypass vulnerability in the Windows File Share Browser and Pulse Secure Collaboration features. A remote, unauthenticated attacker can exploit this to execute arbitrary code on the gateway. This vulnerability has been observed being exploited in the wild.

Affected products

  • Ivanti Pulse Connect Secure 9.0R3 and higher; 9.1R1 and higher

Timeline

  • 2021-04-20: disclosed: Initial discovery/reporting of zero-day exploitation by FireEye/Mandiant
  • 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2021-11-03: advisory: NVD publication date