Stack-based buffer overflow in Ivanti Connect Secure (formerly Pulse Connect Secure) - CVE-2025-0283
Published: January 8, 2025 / Updated: January 22, 2025
Vulnerability identifier: #VU102474
CSH Severity: Low
CVSS v4: 9.3 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H]
CVE-ID: CVE-2025-0283
CWE-ID: CWE-121
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to a boundary error. A local user can trigger a stack-based buffer overflow and execute arbitrary code with elevated privileges.
Affected software
Ivanti Connect Secure (formerly Pulse Connect Secure)
Ivanti Policy Secure (formerly Pulse Policy Secure)
Ivanti Neurons for ZTA gateways
Ivanti Policy Secure (formerly Pulse Policy Secure)
Ivanti Neurons for ZTA gateways
How to mitigate CVE-2025-0283
Install updates from vendor's website.
Ivanti Connect Secure (formerly Pulse Connect Secure) - update to 22.7R2.5
Ivanti Policy Secure (formerly Pulse Policy Secure) - update to 22.7R1.3
Ivanti Neurons for ZTA gateways - update to 22.8R2
Ivanti Policy Secure (formerly Pulse Policy Secure) - update to 22.7R1.3
Ivanti Neurons for ZTA gateways - update to 22.8R2