Sinsinology

Researcher fromwatchTowr Labs
#375of 56,334
468.9Total CVSS
Vulnerabilities · 55
Medium
6
High
41
Critical
8
PT-2025-1003
9
2025-01-08
Ivanti · Ivanti Policy Secure · CVE-2025-0282
**Name of the Vulnerable Software and Affected Versions** Ivanti Connect Secure versions prior to 22.7R2.5 Ivanti Policy Secure versions prior to 22.7R1.2 Ivanti Neurons for ZTA gateways versions prior to 22.7R2.3 **Description** A stack-based buffer overflow exists in the affected software, allowing a remote unauthenticated attacker to achieve remote code execution. This issue has been exploited in the wild by financial institutions and government agencies using an ELF-based remote-access Trojan (RAT) known as DslogdRAT. The exploitation process involves disabling SELinux, preventing syslog forwarding, remounting the drive as read-write, and deploying web shells. Attackers also use a tool called PHASEJAM to display fake update progress bars to deceive administrators and manipulate the Ivanti Integrity Checker Tool (ICT) manifest to bypass integrity checks. Technical analysis of the associated malware reveals the use of the `init config()` function to decrypt configuration buffers via XOR cipher, and the `child()` function to maintain persistence through continuous forking. Networking capabilities are managed by the `test()` function, which utilizes `connectx()` for outbound communication and `listenx()` for inbound connectivity. **Recommendations** Update Ivanti Connect Secure to version 22.7R2.5 or later. Update Ivanti Policy Secure to version 22.7R1.2 or later. Update Ivanti Neurons for ZTA gateways to version 22.7R2.3 or later. Run the external Ivanti ICT tool to verify system integrity.