Target Industry

Indiscriminate, opportunistic targeting.

Overview

Ivanti has released critical security updates to address multiple high-severity vulnerabilities affecting Connect Secure (ICS), Policy Secure (IPS), and Cloud Services Application (CSA). These vulnerabilities, with CVSS scores as high as 9.9, could be exploited by remote authenticated attackers to achieve arbitrary code execution. 

These vulnerabilities are identified as: 

  • CVE-2024-38657 (CVSS 9.1): External file name control in Ivanti Connect Secure (pre-22.7R2.4) and Policy Secure (pre-22.7R1.3) allows remote authenticated attackers with admin privileges to write arbitrary files 
  • CVE-2025-22467 (CVSS 9.9): Stack-based buffer overflow in Ivanti Connect Secure (pre-22.7R2.6) enables remote authenticated attackers to execute arbitrary code 
  • CVE-2024-10644 (CVSS 9.1): Code injection in Ivanti Connect Secure (pre-22.7R2.4) and Policy Secure (pre-22.7R1.3) allows remote authenticated attackers with admin privileges to execute arbitrary code 
  • CVE-2024-47908 (CVSS 9.1): OS command injection in the admin web console of Ivanti CSA (pre-5.0.5) allows remote authenticated attackers with admin privileges to execute arbitrary code. 

Impact

Four critical vulnerabilities in Ivanti products allow remote authenticated attackers to write arbitrary files, execute arbitrary code, and perform command injections, leading to potential system compromise and unauthorised access. 

Detailed Information 

  • CVE-2024-38657 (CVSS 9.1): Allows remote authenticated attackers with admin privileges to write arbitrary files. This can lead to unauthorised file modifications, data corruption, or the introduction of malicious files, compromising system integrity and potentially enabling further attacks. 
  • CVE-2025-22467 (CVSS 9.9): Enables remote authenticated attackers to execute arbitrary code due to a stack-based buffer overflow. This can lead to complete system compromise, allowing attackers to take full control of the affected system, execute malicious code, steal sensitive information, and disrupt services. 
  • CVE-2024-10644 (CVSS 9.1): Allows remote authenticated attackers with admin privileges to inject and execute arbitrary code. This can result in unauthorised actions within the system, including data theft, system manipulation, and potential further exploitation of network-connected resources. 
  • CVE-2024-47908 (CVSS 9.1): Permits remote authenticated attackers with admin privileges to execute arbitrary commands on the operating system via command injection in the admin web console. This can lead to full system compromise, unauthorised access to sensitive data, and the ability to disrupt or manipulate system operations. 

Vulnerability Detection

Multiple Ivanti products are vulnerable to critical security flaws in specific versions, necessitating immediate updates to the latest secure releases. 

CVE-2024-38657 

  • Ivanti Connect Secure versions before 22.7R2.4 
  • Ivanti Policy Secure versions before 22.7R1.3 

CVE-2025-22467  

  • Ivanti Connect Secure versions before 22.7R2.6 

CVE-2024-10644  

  • Ivanti Connect Secure versions before 22.7R2.4 
  • Ivanti Policy Secure versions before 22.7R1.3 

CVE-2024-47908 

  • Ivanti Cloud Services Application (CSA) versions before 5.0.5 

Exploitation

The company has stated that there is no current evidence of these vulnerabilities being exploited in the wild. However, given the history of Ivanti appliances being frequently targeted and weaponised by malicious actors, it is crucial for users to promptly apply the latest security patches. Ensuring these updates are implemented is essential to mitigate the risk of potential exploitation and to maintain the security and integrity of the affected systems. 

Containment, Mitigations & Remediation

A patch has been released to remediate this vulnerability. It is strongly recommended that users apply this update immediately to ensure their systems are protected against potential exploitation.  

Threat Landscape

Ivanti’s products, including Connect Secure and Policy Secure, are widely deployed in enterprise environments across various sectors, including government, healthcare, financial services, energy, and education. These solutions enable secure remote access and support for zero-trust access frameworks, making them high-value targets for cyber attackers. 

Threat Group

No attribution to specific threat actors or groups has been identified at the time of writing. 

Further Information

  1. https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Cloud-Services-Application-CSA-CVE-2024-47908-CVE-2024-11771?language=en_US 
  2. https://cvefeed.io/vuln/detail/CVE-2024-10644 
  3. https://thehackernews.com/2025/02/ivanti-patches-critical-flaws-in.html 
  4. https://vulnerability.circl.lu/bundle/85f9fd3a-b2ef-443b-b091-2cad7418236f 

Further Threat Intelligence from Quorum Cyber

Headquarters

Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ

FLORIDA, USA Office

501 E Kennedy Blvd.
STE 1400
Tampa FL 33602

Ontario, Canada Office

1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7

Contact Us
Address

Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ

501 E Kennedy Blvd
STE 1400
Tampa FL 33602

1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7

HEADQUARTERS
Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ



FLORIDA, USA OFFICE
501 E Kennedy Blvd.
STE 1400
Tampa FL 33602


ONTARIO, CANADA OFFICE
1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7


Legal

Privacy Preference Center

Skip to content