Skip to content
COOEY

EXPOSURES › CVE-2025-22457

CVE-2025-22457

CRITICAL ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2025-04-04 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2025-22457 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 88/100 ransomwarerceexploited-in-wildunpatched

Ivanti Connect Secure gateways suffered a stack-based buffer overflow allowing unauthenticated remote code execution, linked to ransomware.

A stack-based buffer overflow in Ivanti Connect Secure, Policy Secure, and ZTA Gateways allowed unauthenticated attackers to execute remote code, directly enabling ransomware deployment. DIB organizations must verify patch levels on these critical Zero Trust gateways and monitor for exploitation in the wild, as this vulnerability is actively exploited in the CISA KEV catalog.

Shame score — An unauthenticated remote code execution flaw in a Zero Trust gateway was actively exploited in the wild and linked to ransomware, demonstrating severe negligence in patching and threat detection.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Ivanti Connect Secure, Policy Secure, and ZTA Gateways contains a stack-based buffer overflow vulnerability that allows a remote unauthenticated attacker to achieve remote code execution.

AFFECTED FEDRAMP PRODUCTS · 2
PRODUCTSTATUS
Ivanti Neurons for ITSM (Formerly Service Manager)
Ivanti
Authorized
Ivanti Neurons for MDM (Formerly MobileIron)
Ivanti
Authorized