Two critical zero-day vulnerabilities have been discovered in Ivanti Connect Secure VPN and Ivanti Policy Secure appliances that could lead to unauthenticated remote code execution. Ivanti recommends that users should apply the mitigations immediately and stay informed for patches as they are currently being developed.

Security vendor Volexity detected suspicious lateral movement on the network of one of its Network Security Monitoring service customers last December. Upon further investigation and analysis, the company discovered two different zero-day exploits — CVE-2024-21887 and CVE-2023-46805 — that were chained together to achieve unauthenticated remote code execution.

CVE-2024-21887 (CVSS score of 9.1) is a command injection vulnerability, and CVE-2023-46805 (CVSS score of 9.1) is an authentication bypass vulnerability. Both vulnerabilities impact all supported versions of the Ivanti Connect Secure (formerly Pulse Secure) and Ivanti Policy Secure gateways, including versions 9.x and 22.x.

When exploited together they allow threat actors to execute arbitrary commands on the system without requiring authentication. This opens the door to the compromise of a victim network. Ivanti noted in a knowledge base (KB) article that it was aware of less than 20 customers impacted by the vulnerabilities. Google Cloud’s Mandiant identified exploitation as early as last month by a suspected espionage threat actor.

Ivanti users should act on the vulnerabilities ASAP

Ivanti is currently developing patches for these zero-day vulnerabilities, which are expected to be published beginning around January 22. Organizations using Ivanti Connect Secure and Ivanti Policy Secure gateways should follow Ivanti’s KB article and prioritize the application of these patches as soon as they become available.

Meanwhile, Ivanti has created mitigation measures:

  • As it found evidence of threat actors attempting to manipulate Ivanti’s internal integrity checker (ICT), the company advises all customers to run the external ICT on every Connect Secure and Ivanti Policy Secure Gateway system. Mandiant noted this is the simplest way to assess whether the system is already compromised.
  • Ivanti added new functionality to the external ICT that will be incorporated into the internal ICT in the future while providing regular updates. Customers should ensure they are running the latest version of both internal and external ICT.
  • Users should always run the ICT in conjunction with continuous monitoring.

Mandiant urges Ivanti customers to apply the mitigation as soon as possible and warns that running the external ICT will require a system reboot, which will cause customers to lose some volatile data.