Summary: Over 5,000 Ivanti Connect Secure appliances are vulnerable to a critical attack due to a stack-based buffer overflow, tracked as CVE-2025-22457. Although Ivanti released a fix in February, exploitation in the wild has been ongoing, particularly by the Chinese hacking group UNC5221. Users are urged to update their devices immediately as many instances remain unpatched.
Affected: Ivanti Connect Secure and Pulse Connect Secure appliances
Keypoints :
- Over 5,000 unpatched Ivanti Connect Secure appliances are exposed to attacks.
- The CVE-2025-22457 vulnerability could allow remote, unauthenticated attackers to execute code.
- Older Pulse Connect Secure appliances will not receive patches, prompting migration to supported versions.
- Ivanti Connect Secure versions 22.7R2.6 and upcoming patches address this vulnerability.
- Exploitation methods include deploying an in-memory dropper and backdoor by UNC5221.
Source: https://www.securityweek.com/exploited-vulnerability-puts-5000-ivanti-vpn-appliances-at-risk/