CVE-2025-22457
A critical security flaw in certain Ivanti security products allows an attacker to run their own code on the system remotely. This vulnerability is caused by a memory error known as a stack-based buffer overflow.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Users of Ivanti Connect Secure (versions before 22.7R2.6), Ivanti Policy Secure (versions before 22.7R1.4), and Ivanti ZTA Gateways (versions before 22.8R2.2).
Real-world impact
An attacker could take complete control of the affected Ivanti device without needing any login credentials, potentially allowing them to steal sensitive data or disrupt network services.
Why this severity
This vulnerability is rated critical because it allows a remote attacker to execute code with high impact on confidentiality, integrity, and availability, even though it requires high complexity to exploit.
What to do about it
- 01Upgrade Ivanti Connect Secure to version 22.7R2.6 or later.
- 02Upgrade Ivanti Policy Secure to version 22.7R1.4 or later.
- 03Upgrade Ivanti ZTA Gateways to version 22.8R2.2 or later.
- ›Apply mitigations as set forth in the CISA instructions.
CISA KEV required action
Timeline
- Apr 3, 2025 · Apr 3, 2025PublishedDisclosed and added to the National Vulnerability Database.
- Apr 4, 2025 · Apr 4, 2025Confirmed exploited (CISA KEV)CISA added it to the Known Exploited Vulnerabilities catalog — attackers are using it in the wild.
- Apr 11, 2025 · Apr 11, 2025CISA remediation deadlineFederal agencies are required to remediate by this date.
- Aug 4, 2026 · 2d agoAdvisory updatedThe NVD record was last revised.
- Aug 4, 2026 · 2d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.
How it’s attacked
References & advisories
- forums.ivanti.com/s/article/April-Security-Ad…vendor advisory
- cisa.gov/known-exploited-vulnerabili…us government resource