CyberzSOC

Publication detail
← Back to advisories & guidance

Ivanti Releases Security Updates for Connect Secure, Policy Secure, and ZTA Gateways ↗ source

January 8, 2025 CISA Alert

Summary

(Updated April 8, 2025) CISA updated these mitigations based on identification of a new malware variant called RESURGE that could undermine the effectiveness of the mitigations previously provided. For more information on RESURGE, see MAR-25993211.R1.V1.CLEAR and CISA Releases Malware Analysis Report on RESURGE Malware Associated with Ivanti Connect Secure . A cyber threat actor could exploit CVE-2025-0282 to take control of an affected system. CISA has added CVE-2025-0282 to its Known Exploited Vulnerabilities Catalog , based on evidence of active exploitation. Mandiant: Ivanti Connect Secure VPN Targeted in New Zero-Day Exploitation Palo Alto Networks: Threat Brief: CVE-2025-0282 and CVE-2025-0283 (Updated Jan. 17) For all instances of Ivanti Connect Secure, Policy Secure, and ZTA Gateways, see the following steps for general hunting guidance: Conduct threat hunting actions: Run an external Integrity Checker Tool (ICT). Conduct threat hunt actions on any systems connected to—or recently connected to—the affected Ivanti device.

News Coverage

No coverage found in monitored research blogs or news feeds.

CVEs Referenced in This Publication

CVECVSSAffected
CVE-2025-0282 9.0 Critical Ivanti Connect Secure, Policy Secure, and ZTA Gateways Ivanti Connect Secure, Policy Secure, and ZTA Gateways contain a stack-based buffer overflow which can lead to unauthenticated remote code execution.
CVE-2025-0283 7.0 High Ivanti Connect Secure A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7R1.2, and Ivanti Neurons for …

Extracted from the publication text. Each CVE links to its tracked detail page.

Vendors Named in This Publication

Each vendor links to its Known Exploited Vulnerabilities catalog page. Only vendors that appear in the KEV catalog are listed, either because the publication cites one of their KEV entries or because it names them directly.