CVE-2025-0282

CRITICAL(9.0)KEVRansomwareLikely Exploited

Ivanti Connect Secure, Policy Secure, and ZTA Gateways Stack-Based Buffer Overflow Vulnerability

Description

CVE-2025-0282 is a critical stack-based buffer overflow vulnerability affecting Ivanti Connect Secure, Policy Secure, and Neurons for ZTA Gateways. A remote unauthenticated attacker can achieve remote code execution by exploiting this memory corruption flaw in the VPN gateway's pre-authentication code path. Rated CVSS v3.1 9.0 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H), the vulnerability has a changed scope that extends impact beyond the gateway itself. CISA has added it to the KEV catalog with a remediation deadline of January 15, 2025, with confirmed ransomware exploitation. The EPSS score of 0.9412 (99.9th percentile) places it among the most actively exploited vulnerabilities in the current landscape.

KEV Information

Vendor
Ivanti
Product
Connect Secure, Policy Secure, and ZTA Gateways
Date Added
January 8, 2025
Due Date
January 15, 2025
Required Action
Apply mitigations as set forth in the CISA instructions linked below to include conducting hunt activities, taking remediation actions if applicable, and applying updates prior to returning a device to service.

CVSS Score

Vector String
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:HOpen in Calculator
Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
CHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
2.2
Impact Score
6.0

CWEs

Affected Products

VendorProductVersion
ivanticonnect secure22.7
ivantineurons for zero-trust access22.7
ivantipolicy secure22.7

Multiple CVSS Assessments

Source: 3c1d8aa1-5a33-4ea4-8992-aadd6440af75(Secondary)
9.0
CRITICAL

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H

Source: [email protected](Primary)
9.0
CRITICAL

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H

References

Weakness Type

CWE — Unknown

Ivanti has not disclosed specific CWE identifiers for CVE-2025-0282. Based on the vulnerability description, this is a stack-based buffer overflow, which aligns with CWE-121 (Stack-based Buffer Overflow). Stack-based buffer overflows occur when a program writes data beyond the boundaries of a stack-allocated buffer, corrupting adjacent memory including return addresses and saved frame pointers. In the context of Ivanti Connect Secure, the buffer overflow exists in a pre-authentication code path, meaning the vulnerable code processes attacker-controlled input before any authentication check is performed. This allows a remote unauthenticated attacker to corrupt the stack and redirect execution to attacker-supplied code, achieving remote code execution on the VPN gateway.

Impact Analysis

Network Perimeter Breach via VPN Gateway Compromise is the central threat of CVE-2025-0282. Ivanti Connect Secure (formerly Pulse Secure) is a widely deployed SSL VPN solution that serves as the primary remote access gateway for thousands of organizations. Compromising this device gives attackers a foothold inside the corporate network perimeter.

Confidentiality Impact is maximum (C:H). Remote code execution on the VPN gateway provides access to VPN session data, user credentials, authentication tokens, TLS private keys, and configuration data. The changed scope (S:C) means the attacker can reach systems beyond the VPN appliance itself, including internal network resources accessible through the VPN tunnel. VPN credentials can be harvested to establish persistent authenticated access even after the vulnerability is patched.

Integrity Impact is maximum (I:H). The attacker can modify the VPN gateway's configuration, inject malicious code into the device firmware, install web shells and backdoors, alter authentication logic to capture credentials, and modify access control policies to permit unauthorized access. The compromised gateway becomes a man-in-the-middle position for all VPN traffic.

Availability Impact is maximum (A:H). The attacker can disable VPN services, disrupt remote workforce connectivity, corrupt the device's operating system, or use the compromised gateway as a launching point for denial-of-service attacks against internal infrastructure.

Ransomware and Nation-State Exploitation: CISA confirms the ransomware association as "Known." The EPSS score of 0.9412 (99.9th percentile) reflects mass exploitation by both financially motivated threat groups and nation-state actors. Google Threat Intelligence has published detailed analysis of the zero-day exploitation campaign, documenting sophisticated threat actors leveraging this vulnerability for espionage and network compromise operations.

Exploit Maturity

CVE-2025-0282 is one of the most actively exploited vulnerabilities of early 2025, with confirmed zero-day exploitation prior to patch availability. CISA's KEV catalog lists it with the earliest possible remediation deadline of January 15, 2025, and the EPSS score of 0.9412 (99.9th percentile) confirms near-universal targeting by threat actors.

Zero-Day Exploitation Confirmed: This vulnerability was exploited as a zero-day before Ivanti released patches. Google Threat Intelligence published a detailed analysis documenting the initial exploitation campaign, attributing activity to sophisticated threat actors conducting espionage operations. The zero-day exploitation timeline means that organizations running vulnerable Ivanti appliances may have been compromised before patches were available.

Multiple Public Exploits Available: Several public exploit implementations are available, significantly lowering the barrier to exploitation. A Rapid7 exploit (sfewer-r7/CVE-2025-0282) provides a working proof-of-concept, and WatchTowr Labs has published a detailed exploitation walkthrough describing the technical exploitation techniques step by step.

Ransomware Exploitation: CISA classifies the ransomware association as "Known," confirming that ransomware groups have incorporated this vulnerability into their attack operations. VPN gateways are priority targets for ransomware operators because they provide direct, trusted access to internal networks where ransomware can be deployed at scale.

CISA Dedicated Mitigation Guidance: The severity of this vulnerability prompted CISA to publish dedicated mitigation instructions, reflecting the urgency and widespread impact of active exploitation campaigns.

High Attack Complexity Caveat: Despite the massive exploitation activity, the CVSS vector rates attack complexity as high (AC:H), indicating that exploitation requires specific conditions such as precise heap/stack layout knowledge or multiple exploitation attempts. However, the public exploits and detailed technical writeups have effectively reduced the practical complexity for skilled attackers.

Remediation

  1. Update Ivanti Connect Secure to version 22.7R2.5 or later immediately. For Ivanti Policy Secure, update to version 22.7R1.2 or later, and for Ivanti Neurons for ZTA Gateways, update to version 22.7R2.3 or later. Refer to the Ivanti security advisory for detailed upgrade instructions and download links.

  2. Run the Ivanti Integrity Checker Tool (ICT) before and after patching to detect signs of compromise. Given the zero-day exploitation history, devices may have been compromised before patches were applied. The ICT can identify unauthorized modifications to the device's file system that indicate active compromise. Follow CISA's mitigation instructions for detailed guidance on using the ICT and interpreting results.

  3. Perform a factory reset before applying updates if the Integrity Checker Tool detects compromise indicators. A firmware update alone may not remove sophisticated persistence mechanisms. Reset the device to factory defaults, apply the patched firmware from a known-good image, and reconfigure from scratch. Do not restore from backup configurations taken during the vulnerable period, as they may contain backdoors.

  4. Rotate all credentials and certificates associated with the Ivanti deployment after patching. This includes VPN user passwords, RADIUS/LDAP integration credentials, SAML/OAuth certificates, TLS server certificates, administrator passwords, and API keys. Assume that any authentication material accessible to the Ivanti device has been compromised during the exploitation window.

  5. Monitor for post-exploitation activity across your network. Threat actors who compromised Ivanti devices may have established additional persistence mechanisms on internal systems. Review authentication logs for suspicious VPN sessions, check for unauthorized accounts or access on systems accessible through VPN tunnels, and hunt for indicators of compromise documented in the Google Threat Intelligence analysis.

Technical Details

CVE-2025-0282 is a stack-based buffer overflow in Ivanti Connect Secure (before 22.7R2.5), Policy Secure (before 22.7R1.2), and Neurons for ZTA Gateways (before 22.7R2.3) that enables unauthenticated remote code execution through the VPN gateway's pre-authentication processing.

CVSS Vector Breakdown: The vector CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H yields a base score of 9.0. Network attack vector (AV:N) allows remote exploitation from the internet. High attack complexity (AC:H) reflects the exploitation difficulties inherent in stack buffer overflows on hardened systems, including ASLR bypass requirements and precise memory layout dependencies. No privileges (PR:N) and no user interaction (UI:N) are needed, as the vulnerability exists in the pre-authentication code path. The changed scope (S:C) is critical — it indicates the vulnerability allows impact beyond the VPN appliance itself, reaching systems and resources in the internal network. All impact metrics are maximum (C:H/I:H/A:H).

Attack Mechanism: The Ivanti Connect Secure VPN processes incoming network requests through several stages before authentication is enforced. CVE-2025-0282 exists in one of these pre-authentication stages where a stack-allocated buffer is used to process attacker-controlled input. By sending a specially crafted request, the attacker overflows this buffer, corrupting the saved return address on the stack. The attacker overwrites the return address with a pointer to their shellcode or a ROP (Return-Oriented Programming) chain, redirecting execution when the vulnerable function returns. Despite protections like ASLR, the public exploits from Rapid7 and the WatchTowr Labs walkthrough demonstrate techniques to reliably achieve code execution.

Post-Exploitation Behavior: Documented exploitation campaigns install web shells, modify authentication modules to harvest credentials, and establish persistent reverse shell connections. Sophisticated actors have been observed modifying the Ivanti device's integrity checker output to avoid detection, implanting code that survives firmware upgrades, and using the compromised device as a pivot point for lateral movement into internal networks.

Historical Context: Ivanti Connect Secure (formerly Pulse Secure) has been the target of multiple high-profile vulnerability campaigns, including CVE-2023-46805 and CVE-2024-21887. The recurring pattern of critical pre-authentication vulnerabilities in this product line reflects the inherent risk of internet-facing VPN appliances that process complex network protocols before authentication.

Frequently Asked Questions

What is CVE-2025-0282?

CVE-2025-0282 is a critical stack-based buffer overflow in Ivanti Connect Secure, Policy Secure, and Neurons for ZTA Gateways that allows unauthenticated remote code execution. With a CVSS score of 9.0, it was exploited as a zero-day before patches were available and is actively used by both nation-state actors and ransomware groups.

Was CVE-2025-0282 exploited before a patch was available?

Yes. This vulnerability was exploited as a zero-day, meaning threat actors were actively compromising Ivanti devices before Ivanti released the patch. Google Threat Intelligence documented the initial zero-day exploitation campaign. Organizations that were running vulnerable versions during this period should assume potential compromise and run the Integrity Checker Tool.

How do I check if my Ivanti device has been compromised?

Run the Ivanti Integrity Checker Tool (ICT) to scan for unauthorized file system modifications. CISA has published dedicated mitigation instructions for CVE-2025-0282 that include guidance on using the ICT and interpreting results. If compromise is detected, perform a factory reset before applying the patched firmware and reconfigure the device from scratch.

Are public exploits available for CVE-2025-0282?

Yes. Multiple public exploits and detailed technical writeups are available, including a Rapid7 proof-of-concept on GitHub and a comprehensive exploitation walkthrough from WatchTowr Labs. The availability of these resources makes exploitation accessible to a wide range of threat actors, increasing the urgency of patching.

CVSS Score

9.0
CRITICAL(9.0)

EPSS Score

EPSS Score99.97%
EPSS Percentile100.0%

Dates

PublishedJanuary 8, 2025
Last ModifiedAugust 4, 2026
StatusAnalyzed
CVSS Versionv3.1

Need Help With Vulnerability Management?

Our security experts can help you prioritize and remediate vulnerabilities effectively.