PT-2025-1003 · Ivanti · Ivanti Neurons For Zta Gateways+2
CVSS v3.1
9.0
Critical
| Vector | AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Ivanti Connect Secure versions prior to 22.7R2.5
Ivanti Policy Secure versions prior to 22.7R1.2
Ivanti Neurons for ZTA gateways versions prior to 22.7R2.3
Description
A stack-based buffer overflow exists in the affected software, allowing a remote unauthenticated attacker to achieve remote code execution. This issue has been exploited in the wild by financial institutions and government agencies using an ELF-based remote-access Trojan (RAT) known as DslogdRAT. The exploitation process involves disabling SELinux, preventing syslog forwarding, remounting the drive as read-write, and deploying web shells. Attackers also use a tool called PHASEJAM to display fake update progress bars to deceive administrators and manipulate the Ivanti Integrity Checker Tool (ICT) manifest to bypass integrity checks. Technical analysis of the associated malware reveals the use of the
init config() function to decrypt configuration buffers via XOR cipher, and the child() function to maintain persistence through continuous forking. Networking capabilities are managed by the test() function, which utilizes connectx() for outbound communication and listenx() for inbound connectivity.Recommendations
Update Ivanti Connect Secure to version 22.7R2.5 or later.
Update Ivanti Policy Secure to version 22.7R1.2 or later.
Update Ivanti Neurons for ZTA gateways to version 22.7R2.3 or later.
Run the external Ivanti ICT tool to verify system integrity.
Exploit
Fix
LPE
RCE
Memory Corruption
Out of bounds Read
Stack Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ivanti Connect Secure
Ivanti Neurons For Zta Gateways
Ivanti Policy Secure