CVE-2021-22893: Ivanti Pulse Connect Secure Use-After-Free Vulnerability
Ivanti Pulse Connect Secure contains a use-after-free vulnerability that allow a remote, unauthenticated attacker to execute code via license services.
Other sources
Pulse Connect Secure 9.0R3/9.1R1 and higher is vulnerable to an authentication bypass vulnerability exposed by the Windows File Share Browser and Pulse Secure Collaboration features of Pulse Connect Secure that can allow an unauthenticated user to perform remote arbitrary code execution on the Pulse Connect Secure gateway. This vulnerability has been exploited in the wild.
— NVD
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2021-22893.
What is the title of this vulnerability?
The title of this vulnerability is Ivanti Pulse Connect Secure Use-After-Free Vulnerability.
What is the description of this vulnerability?
The description of this vulnerability is that Ivanti Pulse Connect Secure contains a use-after-free vulnerability that allows a remote, unauthenticated attacker to execute code via license services.
Which software is affected by this vulnerability?
The software affected by this vulnerability is Ivanti Pulse Connect Secure.
Where can I find more information about this vulnerability?
You can find more information about this vulnerability [here](https://www.cisa.gov/emergency-directive-21-03).
What is the Common Weakness Enumeration (CWE) ID of this vulnerability?
The Common Weakness Enumeration (CWE) ID of this vulnerability is CWE-416.