CVE-2025-0282: Critical Zero-Day Remote Code Execution Vulnerability Impacts Several Ivanti Products
ID: aa068c0a-2b91-597c-b35f-f9f33b1cc81b
STIX ID: report--aa068c0a-2b91-597c-b35f-f9f33b1cc81b
Feed Name: Arctic Wolf
On January 8, 2025 Arctic Wolf summarized Ivanti advisories for CVE-2025-0282, a critical unauthenticated stack-based buffer overflow in Ivanti Connect Secure that enables remote code execution (exploitation observed only in Connect Secure), and CVE-2025-0283, a related stack overflow requiring local authenticated access. Patches for Connect Secure (22.7R2.5) are available and patches for Policy Secure and Neurons for ZTA Gateways were scheduled for January 21; Arctic Wolf strongly recommends immediate upgrading and following Ivanti's mitigation guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
