Drooid Logo
Back to today’s briefing

Story perspectives

Ivanti Issues Urgent Patches for Critical Zero-Day Vulnerabilities

1/10/2025

36 2

1 of 3

Ivanti Issues Patches
  • Ivanti has issued patches for critical vulnerabilities in Connect Secure, Policy Secure, and ZTA Gateways, identified as CVE-2025-0282 and CVE-2025-0283.
  • CVE-2025-0282 is a zero-day flaw allowing unauthenticated remote code execution, while CVE-2025-0283 permits privilege escalation for authenticated users.
  • Suspected Chinese attackers are linked to the exploitation of CVE-2025-0282, necessitating urgent updates and factory resets.
  • Patches for Policy Secure and ZTA Gateways are anticipated by January 21, 2025.
1 / 3