LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2021-22893: Ivanti Pulse Connect Secure Use-After-Free Vulnerability

RBRecent Breaches Vulnerability Intelligence·Nov 3, 2021
Critical⚠ Actively exploited (CISA KEV)Ransomware-linked
Critical
Severity
Active
CISA KEV
Yes
Ransomware use
May 3, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2021-22893 to its Known Exploited Vulnerabilities catalog on Nov 3, 2021, with a federal patch deadline of May 3, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately. Ransomware crews are known to exploit this flaw.

Ivanti Pulse Connect Secure contains a use-after-free vulnerability that allow a remote, unauthenticated attacker to execute code via license services.

CVE-2021-22893 is a use-after-free vulnerability in Ivanti Pulse Connect Secure that lets a remote, unauthenticated attacker execute code by abusing license services. Because the product is commonly deployed as a remote-access gateway, successful exploitation can give an attacker a foothold on the appliance and a path into the internal network. Public reporting also links the flaw to ransomware activity, so organizations that still run vulnerable instances should treat it as a high-priority risk.

Details such as exact affected builds and scoring must be confirmed against the vendor advisory; the guidance below stays within the published facts and general practices for this class of flaw.

How it works

The vulnerability is described as a use-after-free condition reachable through the license services of Pulse Connect Secure. In a use-after-free, memory that has already been released is later reused; an attacker who can influence that reuse may corrupt program state and gain control of execution. Combined with the stated CWE-287 (improper authentication) characteristic, the attack requires no prior credentials: a remote party simply interacts with the exposed license-related interface.

Once code execution is achieved on the appliance, the attacker can install persistence, harvest credentials, or pivot inward. No further exploit mechanics are supplied in the public summary, so defenders should not assume particular packet formats or shellcode and should instead rely on the vendor’s technical description.

Am I affected? How to find it in your systems

Pulse Connect Secure appliances are typically placed at the network edge to terminate SSL VPN and remote-access sessions. Inventory every instance—physical, virtual, or cloud-hosted—by:

Log and telemetry signs of exploitation are limited in public detail. Look for unexpected processes, new administrative accounts, anomalous license-service traffic, or sudden configuration changes on the appliance. Correlate these with outbound connections that do not match normal VPN client patterns. If the appliance forwards logs to a SIEM, alert on authentication failures or service crashes involving the license component.

How to remediate

The required action is to apply the updates issued by the vendor. Obtain the fixed software package directly from Ivanti’s advisory for CVE-2021-22893, verify its integrity, and install it on every affected appliance following the vendor’s documented procedure. After the update, reboot if instructed and confirm the new version string.

Once patched, harden the remaining attack surface:

If you can't patch immediately

Until the vendor update can be applied, reduce exposure with compensating controls:

These steps do not eliminate the vulnerability; they only buy time until the official patch is installed.

If your data may have been exposed

Actively exploited vulnerabilities of this type have been used in ransomware campaigns, so any unpatched appliance should be assumed potentially compromised until proven otherwise. Perform a full forensic review of the device, reset credentials, and examine internal systems reachable from the VPN for signs of follow-on activity. As an additional check, you can run a free exposure scan of your email addresses against known breach data sets to see whether associated accounts have already appeared in public dumps.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedIvanti · Pulse Connect Secure
WeaknessCWE-287
Added to CISA KEVNov 3, 2021
Federal patch deadlineMay 3, 2022
Known ransomware useYes
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities