{"id":3077,"date":"2025-04-05T10:05:41","date_gmt":"2025-04-05T10:05:41","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/04\/05\/ivanti-connect-secure-rce-vulnerability-actively-exploited-in-the-wild-apply-patch-now\/"},"modified":"2025-04-05T10:05:41","modified_gmt":"2025-04-05T10:05:41","slug":"ivanti-connect-secure-rce-vulnerability-actively-exploited-in-the-wild-apply-patch-now","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/04\/05\/ivanti-connect-secure-rce-vulnerability-actively-exploited-in-the-wild-apply-patch-now\/","title":{"rendered":"Ivanti Connect Secure RCE Vulnerability Actively Exploited in the Wild \u2013 Apply Patch Now!"},"content":{"rendered":"<p>    Ivanti Connect Secure RCE Vulnerability Actively Exploited in the Wild \u2013 Apply Patch Now!<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>Ivanti has disclosed a critical vulnerability, CVE-2025-22457, affecting its Connect Secure, Pulse Connect Secure, Ivanti Policy Secure, and ZTA Gateways products that are actively exploited in the wild.<\/p>\n<p>This stack-based buffer overflow flaw, with a CVSS score of 9.0, has been actively exploited since mid-March 2025, posing significant risks to organizations using these VPN and network access solutions.<\/p>\n<p>CVE-2025-22457 is a stack-based buffer overflow (CWE-121) that allows a remote, unauthenticated attacker to achieve remote code execution (RCE). <\/p>\n<p>The flaw arises from improper input validation, enabling attackers to overflow the buffer and execute arbitrary code. <\/p>\n<ul class=\"wp-block-list\">\n<li>\n<strong>Ivanti Connect Secure<\/strong>: Versions 22.7R2.5 and earlier.<\/li>\n<li>\n<strong>Pulse Connect Secure<\/strong>: Versions 9.1R18.9 and prior (End-of-Support as of December 31, 2024).<\/li>\n<li>\n<strong>Ivanti Policy Secure<\/strong>: Versions 22.7R1.3 and prior.<\/li>\n<li>\n<strong>ZTA Gateways<\/strong>: Versions 22.8R2 and prior.<\/li>\n<\/ul>\n<p>\u201cThis advisory has been updated to make it clear the vulnerability was fully patched in Ivanti Connect Secure\u201d Ivanti Said.<\/p>\n<h2 class=\"wp-block-heading\"><strong>CVE-2025-22457 Exploitation in the Wild<\/strong><\/h2>\n<p>Ivanti disclosed the vulnerability on April 3, 2025, but Mandiant reports exploitation by UNC5221, a suspected Chinese state-sponsored group, since mid-March. UNC5221, known for targeting edge devices, has previously exploited Ivanti zero-days like CVE-2023-46805.<\/p>\n<p><a href=\"https:\/\/cybersecuritynews.com\/chinese-hackers-actively-exploiting-ivanti-vpn-vulnerability\/\" target=\"_blank\" rel=\"noreferrer noopener\">Attackers use CVE-2025-22457 to deploy malware<\/a> such as Trailblaze (an in-memory dropper), Brushfire (a passive backdoor), and the Spawn suite for credential theft and lateral movement. Post-exploitation, they tamper with logs using tools like SPAWNSLOTH to evade detection.<\/p>\n<p>The vulnerability was patched in Ivanti Connect Secure version 22.7R2.6 on February 11, 2025, initially considered a low-risk denial-of-service issue due to its limited character set (periods and numbers). <\/p>\n<p>However, UNC5221 likely reverse-engineered the patch, developing an RCE exploit for unpatched systems, escalating its severity.<\/p>\n<h2 class=\"wp-block-heading\"><strong>Affected Systems and Patch Availability<\/strong><\/h2>\n<p><a href=\"https:\/\/forums.ivanti.com\/s\/article\/April-Security-Advisory-Ivanti-Connect-Secure-Policy-Secure-ZTA-Gateways-CVE-2025-22457?language=en_US\" target=\"_blank\" rel=\"noreferrer noopener nofollow\"><strong>Ivanti confirmed<\/strong><\/a> that a limited number of customers running Ivanti Connect Secure (22.7R2.5 or earlier) and Pulse Connect Secure 9.1x appliances were compromised. Details include:<\/p>\n<ul class=\"wp-block-list\">\n<li>\n<strong>Ivanti Connect Secure<\/strong>: Upgrade to version 22.7R2.6, available at <a href=\"https:\/\/portal.ivanti.com\/\">Ivanti\u2019s portal<\/a>. If compromised, perform a factory reset and redeploy with 22.7R2.6.<\/li>\n<li>\n<strong>Pulse Connect Secure<\/strong>: Contact Ivanti to migrate, as this product is unsupported since December 31, 2024.<\/li>\n<li>\n<strong>Ivanti Policy Secure<\/strong>: A patch (version 22.7R1.4) will be available on April 21, 2025. No exploitation has been observed, and risk is reduced as it\u2019s not internet-facing.<\/li>\n<li>\n<strong>ZTA Gateways<\/strong>: A patch (version 22.8R2.2) will auto-apply on April 19, 2025. Risk exists only for unconnected gateways; no exploitation has been reported.<\/li>\n<\/ul>\n<h2 class=\"wp-block-heading\"><strong>Detection and Mitigation<\/strong><\/h2>\n<p>Ivanti recommends monitoring the Integrity Checker Tool (ICT) for signs of compromise, such as web server crashes. If detected, a factory reset and upgrade to 22.7R2.6 are advised. Mandiant\u2019s blog provides additional indicators of compromise. A post on X by<\/p>\n<p>@nekono_naha on April 4, 2025, noted that of 12,471 exposed Ivanti\/Pulse Connect Secure servers, 66% (8,246) are vulnerable, with 50% (6,049) on pre-9.x versions, highlighting the urgency of patching.<\/p>\n<p>This incident marks Ivanti\u2019s 15th appearance in CISA\u2019s Known Exploited Vulnerabilities catalog since 2024, signaling systemic security challenges with its edge devices. <\/p>\n<p>UNC5221\u2019s involvement underscores the geopolitical stakes, as China-linked actors increasingly target infrastructure for espionage. The delayed disclosure despite the February patch reveals gaps in vulnerability management. <\/p>\n<p>Initially underestimated as a low-risk issue, the flaw\u2019s exploitability allowed attackers a month-long window before public disclosure, emphasizing the need for faster threat intelligence sharing.<\/p>\n<h2 class=\"wp-block-heading\"><strong>Recommendations for Organizations<\/strong><\/h2>\n<p>Organizations should act swiftly:<\/p>\n<ol start=\"1\" class=\"wp-block-list\">\n<li>\n<strong>Patch Immediately<\/strong>: Upgrade to Ivanti Connect Secure 22.7R2.6 or migrate from Pulse Connect Secure.<\/li>\n<li>\n<strong>Monitor for Compromise<\/strong>: Use ICT to detect exploitation and reset if needed.<\/li>\n<li>\n<strong>Limit Exposure<\/strong>: Ensure Policy Secure and ZTA Gateways are not internet-facing.<\/li>\n<li>\n<strong>Enhance Monitoring<\/strong>: Watch for unusual activity like outbound connections or log tampering.<\/li>\n<li>\n<strong>Stay Informed<\/strong>: Check Ivanti\u2019s advisory and Mandiant\u2019s blog for updates.<\/li>\n<\/ol>\n<p>The exploitation of CVE-2025-22457 highlights the persistent threats to network edge devices. As state-sponsored actors like UNC5221 target such vulnerabilities, organizations must prioritize timely patching and secure deployment. <\/p>\n<p>Ivanti\u2019s response addresses supported versions, but legacy systems remain a challenge, underscoring the need for robust cybersecurity practices in an evolving threat landscape.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(135deg,rgb(238,238,238) 100%,rgb(169,184,195) 100%)\"><strong><code><strong><code><strong>Find this News Interesting! Follow us on\u00a0<\/strong><a href=\"https:\/\/news.google.com\/publications\/CAAqBwgKMOffpwsw1Oq_Aw?hl=en-IN&amp;gl=IN&amp;ceid=IN%3Aen\" target=\"_blank\" rel=\"noreferrer noopener\"><strong>Google News<\/strong><\/a><strong>,\u00a0<\/strong><a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener\"><strong>LinkedIn<\/strong><\/a><strong>, and\u00a0<\/strong><a href=\"https:\/\/x.com\/The_Cyber_News\" target=\"_blank\" rel=\"noreferrer noopener\"><strong>X<\/strong><\/a><strong>\u00a0to Get Instant Updates<\/strong><\/code><\/strong><\/code><\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/ivanti-connect-secure-vulnerability-actively-exploited-in-the-wild\/\">Ivanti Connect Secure RCE Vulnerability Actively Exploited in the Wild \u2013 Apply Patch Now!<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Balaji N<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/ivanti-connect-secure-vulnerability-actively-exploited-in-the-wild\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Ivanti Connect Secure RCE Vulnerability Actively Exploited in the Wild \u2013 Apply Patch Now! Ivanti has disclosed a critical vulnerability, CVE-2025-22457, affecting its Connect Secure, Pulse Connect Secure, Ivanti Policy Secure, and ZTA Gateways products that are actively exploited in the wild. This stack-based buffer overflow flaw, with a CVSS score of 9.0, has been [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,131],"tags":[130],"class_list":["post-3077","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-vulnerability","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/3077"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=3077"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/3077\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=3077"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=3077"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=3077"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}