Story perspectives
Ivanti Issues Urgent Patches for Critical Zero-Day Vulnerabilities
1/10/2025
36 2
1 of 3
Ivanti Issues Patches
- Ivanti has issued patches for critical vulnerabilities in Connect Secure, Policy Secure, and ZTA Gateways, identified as CVE-2025-0282 and CVE-2025-0283.
- CVE-2025-0282 is a zero-day flaw allowing unauthenticated remote code execution, while CVE-2025-0283 permits privilege escalation for authenticated users.
- Suspected Chinese attackers are linked to the exploitation of CVE-2025-0282, necessitating urgent updates and factory resets.
- Patches for Policy Secure and ZTA Gateways are anticipated by January 21, 2025.
1 / 3
