Skip to content
COOEY

EXPOSURES › CVE-2025-0282

CVE-2025-0282

CRITICAL ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2025-01-08 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2025-0282 ↗
⚡ RCE ◐ ZERO-DAY ⌖ EXPLOITED IN THE WILD SHAME 85/100 ransomwarerceexploited-in-wildunpatched

Ivanti Connect Secure, Policy Secure, and ZTA Gateways suffered a stack-based buffer overflow allowing unauthenticated remote code execution.

A stack-based buffer overflow in Ivanti's security gateways enables unauthenticated remote code execution, directly compromising Zero Trust Architecture (ZTA) and remote access controls. DIB organizations must urgently patch these products, as the vulnerability is actively exploited in the wild and linked to ransomware campaigns. Failure to patch exposes critical network perimeters to arbitrary code execution, violating CMMC/NIST 800-171 requirements for patch management and system integrity.

Shame score — A critical RCE vulnerability in a Zero Trust gateway was actively exploited in the wild and linked to ransomware, indicating severe negligence in patch management and security hygiene.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Ivanti Connect Secure, Policy Secure, and ZTA Gateways contain a stack-based buffer overflow which can lead to unauthenticated remote code execution.

AFFECTED FEDRAMP PRODUCTS · 2
PRODUCTSTATUS
Ivanti Neurons for ITSM (Formerly Service Manager)
Ivanti
Authorized
Ivanti Neurons for MDM (Formerly MobileIron)
Ivanti
Authorized