THREATOPS
THREAT OPSThreat News › [NVD] CVE-2025-22457 (CRITICAL 9.0) — A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.6, Ivanti Policy Secure before version 22.7R1.4, and Ivanti ZTA Gateways before version 22.8R2.2 allows a remote unauthenticated attacker to achieve remote code execution.

[NVD] CVE-2025-22457 (CRITICAL 9.0) — A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.6, Ivanti Policy Secure before version 22.7R1.4, and Ivanti ZTA Gateways before version 22.8R2.2 allows a remote unauthenticated attacker to achieve remote code execution.

lownvdPublished 2025-04-03

CVE-2025-22457 CVSS: 9.0 CRITICAL Published: 2025-04-03T16:15:35.370

A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.6, Ivanti Policy Secure before version 22.7R1.4, and Ivanti ZTA Gateways before version 22.8R2.2 allows a remote unauthenticated attacker to achieve remote code execution.

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2025-22457