Suspected Chinese government spies have been exploiting a newly disclosed critical bug in Ivanti VPN appliances since mid-March. This is now at least the third time in three years these snoops have been pwning these products. Plus, post-exploit, the Beijing-backed crew deployed on compromised Ivanti equipment two new malware strains along with variants of the Spawn software nasty, we're told. Ivanti today detailed the under-attack 9.0-out-of-10-severity vulnerability, tracked as CVE-2025-22457, and said it affects Ivanti Connect Secure (version 22.7R2.5 and earlier), Pulse Connect Secure 9.x (end-of-support as of December 31), Ivanti Policy Secure, and ZTA gateways. The alert comes just days after the US government warned a new form of Spawn was being used in attacks exploiting an earlier Ivanti zero-day, this one tracked as CVE-2025-0282, in these same products. The new critical bug, CVE-2025-22457, is a stack-based buffer overflow flaw that can lead to unauthenticated remote code execution (RCE); the vendor fixed this in Ivanti Connect Secure 22.7R2.6, released in February. We don't have enough visibility at this time to provide an accurate estimate, but given how fast this threat actor operates, it's imperative that companies move quickly to patch to limit the impact At the time, this CVE was believed to be a low-risk, denial-of-service bug. It turns out the vulnerability wasn't so low risk and could be exploited to achieve RCE, as UNC5221, a suspected Beijing-run espionag...
Suspected Chinese snoops hijacking buggy Ivanti gear — again
The Register
·Jessica Lyons
·Published Apr 3, 2025
·Updated
Affected Software
10 affected components
Ivanti Connect Secure=22.7R2.5
Ivanti Pulse Connect Secure=9.x
Ivanti Policy Secure
Ivanti ZTA gateways
NetScaler ADC
NetScaler Gateway appliances
Ivanti Connect Secure=22.7R2.5
Ivanti Pulse Connect Secure=9.x
Ivanti Policy Secure
Ivanti ZTA gateways
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses how suspected Chinese government spies have exploited a critical vulnerability in Ivanti VPN appliances.
2
What security implications are discussed?
The article highlights the ongoing cyber espionage activity targeting Ivanti products, which presents severe risks to organizations using these systems.
3
What products or software are affected?
The affected products include Ivanti Connect Secure, Ivanti Pulse Connect Secure, Ivanti Policy Secure, and Ivanti ZTA gateways.
4
How long has the vulnerability been exploited?
The vulnerability has been actively exploited since mid-March 2025.
5
Is this the first time these Ivanti products have been targeted?
No, this is at least the third time in three years that these Ivanti products have been compromised by suspected Chinese state actors.