Ivanti Product Security Update Advisory (CVE-2025-22454)
Overview
We have released a security update to fix vulnerabilities in Ivanti products. Users of affected products are advised to update to the latest version.
Affected Products
CVE-2025-22454
Ivanti Secure Access Client (ISAC) Version: ~22.7R3 (inclusive)
Resolved Vulnerabilities
Insufficient Privilege Restriction Vulnerability for Authenticated Local Users (CVE-2025-22454)
Vulnerability Patches
Vulnerability Patches have been made available in the latest updates. Please follow the instructions on the Referenced Sites to update to the latest Vulnerability Patches version.
CVE-2025-22454
Ivanti Secure Access Client (ISAC) versions: 22.7R4, 22.8R1
References
[1] March Security Advisory Ivanti Secure Access Client (ISAC) (CVE-2025-22454)
https://forums.ivanti.com/s/article/March-Security-Advisory-Ivanti-Secure-Access-Client-ISAC-CVE-2025-22454?language=en_US