CVE-2025-22457: Stack-based buffer overflow in Ivanti products

ISGroup Cybersecurity

An unauthenticated remote attacker can execute arbitrary code on vulnerable Ivanti products: Ivanti Connect Secure, a remote SSL VPN solution (versions prior to 22.7R2.6), Ivanti Policy Secure, a network access control solution (versions prior to 22.7R1.4), and Ivanti ZTA Gateways, a SaaS zero trust network access solution (versions prior to 22.8R2.2), due to a stack-based buffer overflow.

ProductIvanti
Date2025-04-18 16:05:21
Information
  • Fix Available
  • Active Exploitation

Technical Summary

The root cause of this issue is the inadequate handling of overly large X-Forwarded-For headers within Ivanti products. By sending a specially crafted HTTP request, an attacker can trigger a stack-based buffer overflow. This memory corruption allows for remote code execution on the target system.

Recommendations

To effectively address and mitigate this critical remote code execution vulnerability, administrators must take the following immediate actions:

  • Update Ivanti Connect Secure: update to a version that includes the fix for CVE-2025-22457. This means updating to:

    • Ivanti Connect Secure 22.7R2.6 or later (released February 11, 2025)

  • Migrate from Pulse Connect Secure: Pulse Connect Secure has reached End of Support (EoS). Ivanti strongly recommends that customers migrate to the latest version of Ivanti Connect Secure to receive security updates and maintain a secure environment.

  • Update Ivanti Policy Secure: update to a version that includes the fix for CVE-2025-22457. This means updating to:

    • Ivanti Policy Secure 22.7R1.4 or later (scheduled for release on April 21, 2025)

  • Update Ivanti ZTA Gateways: update to a version that includes the fix for CVE-2025-22457. This means updating to:

    • Ivanti ZTA Gateways 22.8R2.2 or later (scheduled for release on April 19, 2025)

  • Monitor for suspicious activity: closely monitor Ivanti product logs and network traffic for any signs of exploitation attempts, such as unusual requests with excessively long X-Forwarded-For headers or unexpected system behavior.

Protect your organisation with Threat Intelligence and Digital Risk Protection.

Choose ISGroup for a practical, tailored engagement:

  • A focused assessment of your environment and requirements
  • Clear findings with a prioritised, actionable roadmap
  • Direct support from experienced specialists through remediation and implementation
Talk to an expert