Ivanti VPN Zero-Day Avoided with Device Isolation

The situation regarding Ivanti continues to evolve. On Jan 31, 2024, two new CVEs, which can be leveraged for remote code execution (RCE), were added to the existing advisory. These additional CVEs present a substantial risk to businesses running Ivanti devices. Check Ivanti's website for up-to-date information on patching and remediation.

Virtual private networks (VPNs) are meant to provide a secure network connection for employees. Unfortunately, VPNs can also be attractive targets for threat actors seeking unauthorized access to corporate networks.

On January 10, 2024, Ivanti publicly disclosed two zero-day vulnerabilities impacting Ivanti Connect Secure VPN appliances. When combined, these vulnerabilities allow threat actors to bypass authentication checks and run arbitrary commands, potentially enabling them to execute several cyber attacks. Although no ransomware cases have been reported, the number of exploited devices has steadily grown since disclosure.

If Ivanti users did not apply the vulnerability mitigation — not a patch —upon release on January 10, threat actors may have already compromised their devices. Coalition contacted impacted policyholders almost immediately and, through the combined efforts of several teams, has seen success in avoiding cyber incidents through proactive engagement. 

Previous
Previous

XZ Near Miss Sheds Light on Vulnerability, Patching Issues

Next
Next

A Security Leader’s Guide to Scaling Threat Detection & Response