Stack-based buffer overflow in Ivanti Connect Secure (formerly Pulse Connect Secure) - CVE-2025-0282
Published: January 8, 2025 / Updated: June 13, 2025
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to a boundary error when handling untrusted input. A remote unauthenticated attacker can send specially crafted packets to the system, trigger a stack-based buffer overflow and execute arbitrary code on the target system.
Note, the vulnerability is being actively exploited in the wild against Ivanti Connect Secure instances.
Affected software
Ivanti Policy Secure (formerly Pulse Policy Secure)
Ivanti Neurons for ZTA gateways
How to mitigate CVE-2025-0282
Ivanti Policy Secure (formerly Pulse Policy Secure) - update to 22.7R1.3
Ivanti Neurons for ZTA gateways - update to 22.8R2
Links to Public Exploits and PoC-codes
- Exploit #11340 - CVE-2025-0282 (April 25, 2025)
- Exploit #11205 - Ivanti-CVE-2025-0282 (March 14, 2025)
- Exploit #11180 - CVE-2025-0282 (February 25, 2025)
- Exploit #11105 - CVE-2025-0282 (January 31, 2025)
- Exploit #11086 - CVE-2025-0282 (Exploit for CVE-2025-0282: A remote unauthenticated stack based buffer overflow affecting Ivanti Connect Secure, Ivanti Policy Secure, and Ivanti Neurons for ZTA gateways) (January 23, 2025)
- Exploit #11077 - CVE-2025-0282 (January 17, 2025)
- Exploit #11066 - CVE-2025-0282-Ivanti-exploit (January 15, 2025)