CVE-2025-22454

CVSS 3.1 Score 7.8 of 10 (high)

Details

Published Mar 11, 2025
CWE ID 732

Summary

CVE-2025-22454 is a vulnerability affecting Ivanti Secure Access Client versions prior to 22.7R4. This issue stems from insufficiently restrictive permissions, granting local authenticated attackers the ability to escalate their privileges. By exploiting this vulnerability, attackers can elevate their access level, potentially gaining unrestricted access to sensitive information or system functionality. This privilege escalation poses a significant risk, emphasizing the importance of updating Ivanti Secure Access Client to the latest version to mitigate this threat.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Ivanti Secure Access Client

Affected Vendors

  • Ivanti