Executive brief
A buffer overflow vulnerability in Ivanti Pulse Connect Secure (formerly Pulse Secure) allows a remote authenticated attacker to execute arbitrary code as the root user. The exploit is triggered via a maliciously crafted meeting room within the Collaboration Suite.
Affected products
- Ivanti Pulse Connect Secure before 9.1R11.4
Timeline
- 2021-11-03: disclosed
- 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities catalog.
- 2021-11-03: advisory