• News/
  • https://www.darkreading.com/vulnerabilities-threats/critical-ivanti-rce-bug

Threat Actors Exploit a Critical Ivanti RCE Bug, Again

Dark Reading
·
Nate Nelson
·
Published Jan 10, 2025
·
Updated

A Chinese threat actor is once again exploiting Ivanti remote access devices at large. If you had a nickel for every high-profile vulnerability affecting Ivanti appliances last year, you'd have a lot of nickels. There was the critical >authentication bypass in its Virtual Traffic Manager (vTM), the SQL injection bug in its Endpoint Manager, a trio affecting its Cloud Services Appliance (CSA), critical issues with its Standalone Sentry and Neurons for IT Service Management (ITSM), plus dozens more. It all started last January, when two serious vulnerabilities were discovered in Ivanti's Connect Secure (ICS) and Policy Secure gateways. By the time of disclosure, the vulnerabilities were already being exploited by a suspected Chinese-nexus threat actor, UNC5337, believed to be an entity of UNC5221. Now, one year and one secure-by-design pledge later, threat actors have returned to haunt Ivanti all over again, via a new critical vulnerability in ICS which also affects Policy Secure and Neurons for Zero Trust Access (ZTA) gateways. Ivanti has further warned of a second, slightly less severe bug that hasn't been observed in exploits yet. "Just because we're seeing these often doesn't necessarily mean that they're easy to pull off — it's a highly sophisticated group that is doing this," Arctic Wolf CISO Adam Marrè points out, in defense of the downtrodden IT vendor. "Engineering is not easy, and secure engineering is even more difficult. So even though you may be following the princ...

Read full article

Affected Software

8 affected components
Ivanti Connect Secure
Ivanti Policy Secure
Ivanti Neurons for Zero Trust Access
Ivanti Connect Secure=ICS versions prior to 22.7R2.5
Ivanti Policy Secure=before 22.7R1.2
Ivanti Neurons for Zero Trust Access=before 22.7R2.3
Ivanti Connect Secure
Ivanti Policy Secure
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses the exploitation of a critical remote code execution (RCE) vulnerability in Ivanti's remote access devices by a Chinese threat actor.

2

What security implications are discussed?

The article highlights the risks posed by ongoing exploitation of security vulnerabilities in Ivanti appliances, which can lead to unauthorized access and potential data breaches.

3

What products or software are affected?

The affected products include Ivanti Connect Secure, Ivanti Policy Secure, and Ivanti Neurons for Zero Trust Access.

4

Which versions of Ivanti products are vulnerable?

Vulnerable versions include Ivanti Connect Secure before 22.7R2.5, Ivanti Policy Secure before 22.7R1.2, and Ivanti Neurons for Zero Trust Access before 22.7R2.3.

5

What should users of Ivanti products do in response to this vulnerability?

Users of Ivanti products are advised to update their software to the latest versions to mitigate the risk of exploitation from this critical vulnerability.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203