Executive brief
A stack-based buffer overflow in Ivanti Connect Secure, Policy Secure, and Neurons for ZTA gateways allows a remote unauthenticated attacker to achieve remote code execution. The vulnerability has been observed being exploited in the wild as a zero-day.
Affected products
- Ivanti Connect Secure before 22.7R2.5
- Ivanti Policy Secure before 22.7R1.2
- Ivanti Neurons for ZTA gateways before 22.7R2.3
Timeline
- 2025-01-08: disclosed
- 2025-01-08: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2025-01-08: advisory: Vendor advisory published by Ivanti
- 2025-01-08: exploited: Reported as exploited in the wild by Google Cloud/Mandiant and CISA