Get a Demo
Under Attack?
A warning icon in a triangular shape is centered against a pink background. Text below reads: Zero-Day Exploitation of Ivanti Connect Secure VPN Devices (CVE-2025-0282 & CVE-2025-0283). The Upwind logo is in the top right corner.

New Zero-Day Exploitation of Ivanti Connect Secure VPN Devices with CVE-2025-0282 and CVE-2025-0283

January 09, 2025

New Zero-Day Exploitation of Ivanti Connect Secure VPN Devices with CVE-2025-0282 and CVE-2025-0283

On January 8, 2025, Ivanti announced two critical vulnerabilities impacting its Connect Secure (ICS) VPN appliances: CVE-2025-0282 and CVE-2025-0283. Notably, CVE-2025-0282 has been actively exploited in the wild since mid-December 2024. This vulnerability, an unauthenticated stack-based buffer overflow, allows remote code execution without authentication, posing a serious risk of further network compromise.

Discovery and Response

Affected customers initially identified compromises through Ivanti’s Integrity Checker Tool (ICT) and other security solutions. Ivanti has released patches addressing these vulnerabilities. Organizations using ICS appliances are strongly advised to apply these patches and follow Ivanti’s Security Advisory to safeguard their systems.

Mandiant has been analyzing compromised devices across multiple organizations, uncovering the deployment of known and new malware families. These include the SPAWN malware ecosystem—comprising SPAWNANT (installer), SPAWNMOLE (tunneler), and SPAWNSNAIL (SSH backdoor)—alongside new malware families DRYHOOK and PHASEJAM. While some activity has been linked to the UNC5337 group, broader attribution remains inconclusive, suggesting the possibility of multiple threat actors exploiting CVE-2025-0282.

Impact 

CVE-2025-0282

Exploitation of CVE-2025-0282 involves version-specific attacks, with adversaries performing reconnaissance using HTTP requests to identify appliance versions.Once the target version is identified, attackers disable key security features, such as SELinux and syslog forwarding, and remount the appliance’s filesystem for write access. Following this, web shells are deployed to maintain persistence and facilitate remote access.

CVE-2025-0283 

CVE-2025-0283 is another vulnerability affecting Ivanti Connect Secure appliances. Ivanti has released fewer details about its exact nature as of January 9, 2025. Although less is known about the impact of this vulnerability and there is currently no indication that it is being exploited in the wild, it should also be prioritized for remediation as it has the potential to be exploited along with CVE-2025-0282 in a more complex attack scenario.

Affected Versions

CVE-2025-0282 

  • Invanti Connect Secure
    • Affected versions 22.7R2 through 22.7R2.4 
    • Affected package: cpe:2.3:a:ivanti:connect_secure:22.7:R2.4:*:*:*:*.*.* 
  • Ivanti Policy Secure
    • Affected versions 22.7R1 through 22.7R1.2 
    • Affected package: cpe:2.3:a:ivanti:policy_secure:22.7:r1.2:*:*:*:*.*. 
  • Ivanti Neurons for ZTA gateways
    • Affected versions 22.7R2 through 22.7R2.3 

CVE-2025-0283 

  • Ivanti Connect Secure
    • Affected versions 22.7R2.4 and prior and 9.1R18.9 and prior
    • Affected package: cpe:2.3:a:ivanti:connect_secure:22.7:R2.4:*:*:*:*.*.*
  • Ivanti Policy Secure
    • Affected versions 22.7R1.2 and prior
    • Affected package: cpe:2.3:a:ivanti:policy_secure:22.7:r1.2:*:*:*:*.*. 

Indicators of Compromise (IoCs)

Mandiant has observed the following indicators of compromise in the wild: 

Code FamilyFilenameDescription
DRYHOOKn/aCredential Theft Tool
PHASEJAM/tmp/sWeb Shell dropper
PHASEJAM Webshell/home/webserver/htdocs/dana-na/auth/getComponent.cgiWeb Shell
PHASEJAM Webshell/home/webserver/htdocs/dana-na/auth/restAuth.cgiWeb Shell
SPAWNSNAIL/root/home/lib/libsshd.soSSH backdoor
SPAWNMOLE/root/home/lib/libsocks5.soTunneler
SPAWNANT/root/lib/libupgrade.soInstaller
SPAWNSLOTH/tmp/.liblogblock.soLog tampering utility
  • Update Ivanti Connect Secure to version 22.7R2.5
  • For Invanti Neurons for ZTA gateways and Ivanti Policy Secure, there is currently no patch available. Ivanti has updated that they expect patches to be released on January 21, 2025.

Ivanti advises using their Integrity Checker Tool (ICT) for both external and internal scans to identify potential issues and recommends reaching out to Ivanti Support if any suspicious activity is detected. Although threat actors have attempted to bypass detection by the ICT, Ivanti has provided examples demonstrating the differences between successful scans and unsuccessful ones on compromised devices to help users identify potential compromises.

If an ICT scan indicates compromise, Ivanti recommends that security teams perform a factory reset to remove malware and then reinstall the appliance using version 22.7R2.5. We will continue to update as additional patches are released. 

Contents

Further Reading

OpenAI Breach

Everyone Read the OpenAI Breach as a Model Story, But It Was a Runtime Story

Key Takeaways Autonomous AI agents can now break out of a sandbox, cross an internal network, and breach a production system with no human at the keyboard. OpenAI's evaluation that hacked Hugging Face this month is the clearest proof on record. Most of the coverage read it as a story about a model turning dangerous.…
upwind-identities

Introducing the Upwind Identity Graph: End-to-End Identity Security

Identity used to be treated as a directory problem: find the user, inspect the groups, review the assigned roles, and decide whether the account has too much access. That model no longer matches the cloud. A single person may authenticate through Okta, inherit permissions from multiple groups, receive role assignments in more than one cloud,…
AI-Graph

Introducing the Upwind AI Graph: Extending AI Inventory Beyond Cloud Infrastructure

As enterprise adoption of artificial intelligence accelerates, modern AI infrastructure has expanded far beyond traditional cloud perimeters. Securing enterprise AI today requires complete visibility across four distinct operational layers: Traditional cloud security tools stop at the cloud provider boundary. When enterprise teams connect directly to external AI Providers, security teams lose sight of access paths,…
Add the Upwind RSS Feed to Slack
Connect the Upwind RSS Feed to your Slack.
Follow the how-to here.
Threat RSS
Add the Upwind RSS Feed to Slack
Connect the Upwind RSS Feed to your Slack.
Follow the how-to here.
Main RSS