cloud.google.com
Critical Remote Code Execution Vulnerability Exploited by China-Nexus Actor
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
On April 3, 2025, Ivanti disclosed CVE-2025-22457, a critical buffer overflow vulnerability affecting Ivanti Connect Secure and other products. The vulnerability allows unauthenticated remote code execution, and evidence of exploitation was observed in mid-March 2025. Threat actor UNC5221, linked to China, successfully exploited the vulnerability, deploying new malware families TRAILBLAZE and BRUSHFIRE. The patch for this vulnerability was released on February 11, 2025, but the threat actor managed to reverse engineer it to exploit earlier versions. Ivanti and Mandiant have urged customers to upgrade their systems immediately to mitigate the risk. The incident highlights the ongoing threat posed by state-sponsored actors who can exploit vulnerabilities even after patches are issued.
Key Points: • CVE-2025-22457 allows unauthenticated remote code execution in Ivanti products. • Exploitation was confirmed by Mandiant, with evidence dating back to mid-March 2025. • Threat actor UNC5221, linked to China, deployed new malware following the exploit.