PT-2025-1003 · Ivanti · Ivanti Neurons For Zta Gateways+2

·

CVE-2025-0282

·

Published

2025-01-08

·

Updated

2026-09-02

CVSS v3.1

9.0

Critical

VectorAV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Ivanti Connect Secure versions prior to 22.7R2.5 Ivanti Policy Secure versions prior to 22.7R1.2 Ivanti Neurons for ZTA gateways versions prior to 22.7R2.3
Description A stack-based buffer overflow exists in the affected software, allowing a remote unauthenticated attacker to achieve remote code execution. This issue has been exploited in the wild by financial institutions and government agencies using an ELF-based remote-access Trojan (RAT) known as DslogdRAT. The exploitation process involves disabling SELinux, preventing syslog forwarding, remounting the drive as read-write, and deploying web shells. Attackers also use a tool called PHASEJAM to display fake update progress bars to deceive administrators and manipulate the Ivanti Integrity Checker Tool (ICT) manifest to bypass integrity checks. Technical analysis of the associated malware reveals the use of the init config() function to decrypt configuration buffers via XOR cipher, and the child() function to maintain persistence through continuous forking. Networking capabilities are managed by the test() function, which utilizes connectx() for outbound communication and listenx() for inbound connectivity.
Recommendations Update Ivanti Connect Secure to version 22.7R2.5 or later. Update Ivanti Policy Secure to version 22.7R1.2 or later. Update Ivanti Neurons for ZTA gateways to version 22.7R2.3 or later. Run the external Ivanti ICT tool to verify system integrity.

Exploit

Fix

LPE

RCE

Memory Corruption

Out of bounds Read

Stack Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-00108
BDU:2025-00224
CVE-2025-0282

Affected Products

Ivanti Connect Secure
Ivanti Neurons For Zta Gateways
Ivanti Policy Secure