EXPOSURES › CVE-2025-22457
CVE-2025-22457
CRITICAL ⌖ ON CISA KEV · EXPLOITEDIvanti Connect Secure gateways suffered a stack-based buffer overflow allowing unauthenticated remote code execution, linked to ransomware.
A stack-based buffer overflow in Ivanti Connect Secure, Policy Secure, and ZTA Gateways allowed unauthenticated attackers to execute remote code, directly enabling ransomware deployment. DIB organizations must verify patch levels on these critical Zero Trust gateways and monitor for exploitation in the wild, as this vulnerability is actively exploited in the CISA KEV catalog.
Shame score — An unauthenticated remote code execution flaw in a Zero Trust gateway was actively exploited in the wild and linked to ransomware, demonstrating severe negligence in patching and threat detection.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Ivanti Connect Secure, Policy Secure, and ZTA Gateways contains a stack-based buffer overflow vulnerability that allows a remote unauthenticated attacker to achieve remote code execution.
| PRODUCT | STATUS |
|---|---|
| Ivanti Neurons for ITSM (Formerly Service Manager) Ivanti |
Authorized |
| Ivanti Neurons for MDM (Formerly MobileIron) Ivanti |
Authorized |