March Security Advisory Ivanti Secure Access Client (ISAC) (CVE-2025-22454)

Vulnerability Details

Basic Information

Title March Security Advisory Ivanti Secure Access Client (ISAC) (CVE-2025-22454)
Type ivanti
Published 2025-11-03T13:52:58
Last Seen 2025-04-23T07:46:15
CVSS Score 7.8 (HIGH)

CVSS v3 Details

Attack Vector LOCAL
Attack Complexity LOW
Privileges Required LOW
User Interaction NONE
Scope UNCHANGED
Confidentiality Impact HIGH
Integrity Impact HIGH
Availability Impact HIGH

CVE Information

CVE IDs CVE-2025-22454
CWE
Bulletin Family software

Description

**Summary**

Ivanti has released updates for Ivanti Secure Access Client (ISAC) which addresses one high severity vulnerability. Successful exploitation could lead to privilege escalation.

We are not aware of any customers being exploited by these vulnerabilities at the time of disclosure.

**Vulnerability Details:**

**CVE Number**| **Description**| **CVSS Score (Severity)**| **CVSS Vector**| **CWE**| **Impacted Product(s)**
—|—|—|—|—|—
CVE-2025-22454| Insufficiently restrictive permissions in Ivanti Secure Access Client before 22.7R4 allows a local authenticated attacker to escalate their privileges. | 7.8 (High)| CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H| CWE-732| Secure Access Client (Windows only)

**Affected Versions**

**Product Name**| **Affected Version(s)**| **Affected CPE(s)**| **Resolved Version(s)**| **Patch Availability**
—|—|—|—|—
Ivanti Secure Access Client (ISAC)| 22.7R3 and prior| cpe:2.3:a:ivanti:secure_access_client:22.7:r3:*:*:*:*:*:*| 22.7R4 22.8R1| Download Portal https://portal.ivanti.com/

**Solution**

The resolved versions of the product can be accessed in the download portal (Login Required):

* Ivanti Secure Access Client 22.7R4
* Ivanti Secure Access Client 22.8R1

**Acknowledgements**

Ivanti would like to thank the following for reporting the relevant issues and for working with Ivanti to help protect our customers:

* Naor Hodorov of Hackerone

_Note: Ivanti is dedicated to ensuring the security and integrity of our enterprise software products. We recognize the vital role that security researchers, ethical hackers, and the broader security community play in identifying and reporting vulnerabilities. Visit_ _HERE_ _to learn more about our Vulnerability Disclosure Policy._

**FAQ**

1. **Are you aware of any active exploitation of these vulnerabilities?**

We are not aware of any customers being exploited by these vulnerabilities prior to public disclosure. These vulnerabilities were disclosed through our responsible disclosure program.

2. **How can I tell if I have been compromised?**
Currently, there is no known public exploitation of this vulnerability that could be used to provide a list of indicators of compromise.
3. **What should I do if I need help?**

**** If you have questions after reviewing this information, you can log a case and/or request a call via the** Success Portal**

Impact Assessment

Base Score 7.8
Severity HIGH

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.