Cyber Security

Ivanti Connect Secure Vulnerabilities Let Attackers Execute Code Remotely

Ivanti has disclosed a critical vulnerability, CVE-2025-22467, impacting its Connect Secure (ICS) product.  This stack-based buffer overflow vulnerability, rated 9.9 (Critical) on the CVSS v3.1 scale, allows remote authenticated attackers to execute arbitrary code on affected systems. 

The flaw is present in versions up to 22.7R2.5 and has been addressed in the latest release, 22.7R2.6.

Stack-based Buffer Overflow in Ivanti Connect Secure

CVE-2025-22467 is classified under CWE-121: Stack-Based Buffer Overflow, a common and critical vulnerability type that occurs when data written to a buffer exceeds its allocated size, corrupting adjacent memory locations. 

This specific flaw allows attackers with low privileges to exploit the system remotely without user interaction

The attack vector is network-based, with low complexity, and it can compromise confidentiality, integrity, and availability at a high impact level.

“We are not aware of any customers being exploited by these vulnerabilities prior to public disclosure”, reads the advisory.

Affected Versions and Resolutions

The following table outlines the affected and resolved versions:

Product NameAffected VersionsResolved Versions
Ivanti Connect Secure22.7R2.5 and below22.7R2.6

Mitigation Steps

Ivanti urges all users to update their systems immediately to version 22.7R2.6 or later to mitigate the risk of exploitation. For organizations unable to patch immediately, Ivanti recommends the following interim measures:

  • Network Segmentation: Restrict access to vulnerable systems.
  • Monitoring: Continuously review logs for unauthorized access or suspicious activities.
  • Least Privilege Principle: Limit user account permissions.
  • Factory Reset: For compromised devices, perform a factory reset before upgrading.

This disclosure follows a series of vulnerabilities reported in Ivanti products over recent years, including code injection flaws (CVE-2024-10644) and arbitrary file read issues (CVE-2024-12058). 

Historical exploitation of Ivanti Connect Secure has been observed by advanced persistent threat (APT) groups and cybercriminals targeting similar vulnerabilities.

The critical nature of CVE-2025-22467 highlights the importance of maintaining up-to-date software and implementing robust cybersecurity practices. 

Organizations using Ivanti Connect Secure should prioritize patching their systems to version 22.7R2.6 or later without delay.

Kaaviya

Kaaviya is a Security Editor and fellow reporter with Cyber Security News. She is covering various cyber security incidents happening in the Cyber Space.

Recent Posts

Google Chrome 153 Update Fixes 42 Security Flaws, Including 3 Critical Ones

Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…

3 hours ago

CISA and NIST Release Technical Checklist for Safeguarding Identity Tokens From Theft and Misuse

The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology…

13 hours ago

CISA Shares 17 Techniques Used by Hackers to Compromise Active Directory Environments

CISA and five international cybersecurity agencies have released detailed guidance describing 17 common techniques hackers…

14 hours ago

Apple Rolls Out Massive Security Update Fixing 273 Vulnerabilities Across Its Devices

Apple has released one of its largest coordinated security rollouts, addressing 273 distinct critical vulnerabilities…

14 hours ago

How to Keep Malware’s Rotating Infrastructure From Becoming a Detection Gap

You can’t detect today's attacks with yesterday’s threat intelligence; that’s how you could briefly formulate…

14 hours ago

Microsoft Bans Its AI Models From Launching Cyberattacks or Escalating Their Own Access

Microsoft has published a draft Humanist AI Code of Conduct that would prohibit its in-house…

15 hours ago