Ivanti Product Security Update Advisory (CVE-2025-22454)

Ivanti Product Security Update Advisory (CVE-2025-22454)

Overview

We have released a security update to fix vulnerabilities in Ivanti products. Users of affected products are advised to update to the latest version.
 

 

Affected Products

 

CVE-2025-22454

Ivanti Secure Access Client (ISAC) Version: ~22.7R3 (inclusive)

 

 

Resolved Vulnerabilities

Insufficient Privilege Restriction Vulnerability for Authenticated Local Users (CVE-2025-22454)

 

 

Vulnerability Patches

Vulnerability Patches have been made available in the latest updates. Please follow the instructions on the Referenced Sites to update to the latest Vulnerability Patches version.
 

 

CVE-2025-22454

Ivanti Secure Access Client (ISAC) versions: 22.7R4, 22.8R1

 

 

References

[1] March Security Advisory Ivanti Secure Access Client (ISAC) (CVE-2025-22454)
https://forums.ivanti.com/s/article/March-Security-Advisory-Ivanti-Secure-Access-Client-ISAC-CVE-2025-22454?language=en_US