Ivanti Connect Secure, Policy Secure, and Neurons for ZTA Gateways Privilege Escalation Vulnerability

Vulnerability

A stack-based buffer overflow vulnerability has been identified in Ivanti Connect Secure versions prior to 22.7R2.5, Ivanti Policy Secure versions prior to 22.7R1.2, and Ivanti Neurons for ZTA gateways versions prior to 22.7R2.3. This vulnerability allows a local authenticated attacker to escalate privileges.

Impact

Exploitation of this vulnerability could lead to unauthorized privilege escalation.

Remediation

Users of Ivanti Connect Secure should upgrade to version 22.7R2.5. For Ivanti Policy Secure, the fix will be available in version 22.7R1.3, scheduled for release on January 21, 2025. Ivanti Neurons for ZTA Gateways have already been updated to the patched version 22.8R2.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
3.4
impact
7.5
exploitability
4.0
remediation
7.7
relevance
0.0
threat
0.8
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.