Stack-based buffer overflow in Ivanti Connect Secure (formerly Pulse Connect Secure) - CVE-2025-0283

 

Stack-based buffer overflow in Ivanti Connect Secure (formerly Pulse Connect Secure) - CVE-2025-0283

Published: January 8, 2025 / Updated: January 22, 2025


Vulnerability identifier: #VU102474
CSH Severity: Low
CVSS v4: 9.3 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H]
CVE-ID: CVE-2025-0283
CWE-ID: CWE-121
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to a boundary error. A local user can trigger a stack-based buffer overflow and execute arbitrary code with elevated privileges.


Affected software

Ivanti Connect Secure (formerly Pulse Connect Secure)
Ivanti Policy Secure (formerly Pulse Policy Secure)
Ivanti Neurons for ZTA gateways

How to mitigate CVE-2025-0283

Install updates from vendor's website.

Ivanti Connect Secure (formerly Pulse Connect Secure) - update to 22.7R2.5
Ivanti Policy Secure (formerly Pulse Policy Secure) - update to 22.7R1.3
Ivanti Neurons for ZTA gateways - update to 22.8R2

External References

Related Security Bulletins