
Exploit for CVE-2025-0282: A remote unauthenticated stack based buffer overflow affecting Ivanti Connect Secure, Ivanti Policy Secure, and Ivanti Neurons for ZTA gateways
Remote Unauthenticated Stack Buffer Overflow in Ivanti Products
This proof-of-concept demonstrates exploitation of CVE-2025-0282, a critical vulnerability affecting:
Based on watchTowr's research, this PoC uses a ROP chain targeting Ivanti Connect Secure 22.7r2.4 specifically. Other versions require custom ROP chain development.
The payload creates a new privileged admin account with:
adminpasswordrequests, pyopensslpython3 CVE-2025-0282.py -t <TARGET_IP> -p 443