← Vulnerability feed

Vulnerability record · CVE-2021-22908 · published 27 May 2021

CVE-2021-22908: Ivanti Pulse Connect Secure Windows File Resource Profiles buffer overflow

Ivanti · Connect Secure

A buffer overflow exists in the Windows File Resource Profiles feature of Pulse Connect Secure 9.x. A remote authenticated user who can browse SMB shares can trigger it to run code as root. The feature is not enabled by default as of 9.1R3, so exposure depends on configuration.

8.8 CVSS 3.1 High EPSS 69% · top 0.7% CWE-120 · Classic buffer overflow
8.8CVSS 3.1 base score, v2 9.0
69%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
3References
17 Jun 2026Last modified by NVD

Description

A buffer overflow vulnerability exists in Windows File Resource Profiles in 9.X allows a remote authenticated user with privileges to browse SMB shares to execute arbitrary code as the root user. As of version 9.1R3, this permission is not enabled by default.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

high priorityRemote authenticated code execution as root on a VPN gateway is severe, and the very high EPSS score signals likely exploitation pressure despite no KEV listing.

What it is

A buffer overflow exists in the Windows File Resource Profiles feature of Pulse Connect Secure 9.x. A remote authenticated user who can browse SMB shares can trigger it to run code as root. The feature is not enabled by default as of 9.1R3, so exposure depends on configuration.

Impact

An attacker with SMB browse privileges gains arbitrary code execution as root on the appliance, giving full control of the VPN gateway and any credentials or sessions it handles.

Attack surface

Reached over the network via SMB share browsing through the Windows File Resource Profiles feature; the vector requires low privileges (an authenticated user) and no user interaction.

Exploitation

Not listed in CISA KEV and no public exploit tag appears in the references, but EPSS is very high (0.69377, 99.3rd percentile), indicating elevated predicted exploitation activity.

What to do

  • Apply the vendor fix from Pulse Secure advisory SA44800 for the affected 9.x release.
  • If patching is delayed, disable or restrict the Windows File Resource Profiles feature, which is off by default from 9.1R3.
  • Limit SMB share browsing permissions to only the accounts that truly need it.
  • Monitor and restrict outbound SMB traffic from the appliance to trusted file servers only.
  • Review appliance accounts for unnecessary browse privileges and remove them.

Detection

  • Alert on unexpected process creation or shell activity on the Connect Secure appliance.
  • Monitor SMB traffic from the appliance to internal file servers for anomalous or malformed requests.
  • Audit configuration changes that enable Windows File Resource Profiles.
  • Review appliance logs for crashes or restarts of the file resource service.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-22908 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2021-22893Ivanti Pulse Connect Secure authentication bypass and use-after-free enabling RCEPulse Connect Secure 9.0R3/9.1R1 and higher contains an authentication bypass exposed through the Windows File Share Browser and Pulse Secure Collabo…KEVEPSS 47%analysed10.0CVE-2019-11510Pulse Connect Secure path traversal allows unauthenticated file readPulse Connect Secure versions 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4 contain a path traversal (CWE-22) flaw. An unauthentica…KEVEPSS 100%analysed9.8CVE-2025-22457Ivanti Connect Secure, Policy Secure and ZTA Gateways stack buffer overflow RCEA stack-based buffer overflow (CWE-121/CWE-787) in Ivanti Connect Secure, Policy Secure and ZTA Gateways allows a remote, unauthenticated attacker to…KEVEPSS 100%analysed9.1CVE-2024-21887Ivanti Connect Secure and Policy Secure web component command injectionIvanti Connect Secure and Policy Secure (9.x, 22.x) contain a command injection flaw (CWE-77) in web components. An authenticated administrator can s…KEVEPSS 100%analysed9.0CVE-2025-0282Ivanti Connect Secure stack buffer overflow enables unauthenticated RCEA stack-based buffer overflow (CWE-121/CWE-787) in Ivanti Connect Secure, Policy Secure and Neurons for ZTA gateways lets a remote, unauthenticated a…KEVEPSS 100%analysed8.8CVE-2021-22894Pulse Connect Secure buffer overflow allows root code executionPulse Connect Secure before 9.1R11.4 contains a buffer overflow reachable through a maliciously crafted meeting room. A remote authenticated attacker…KEVEPSS 41%analysed8.8CVE-2021-22899Pulse Connect Secure command injection via Windows Resource ProfilesPulse Connect Secure before 9.1R11.4 contains a command injection flaw (CWE-77) in the Windows Resource Profiles feature. An attacker who can authent…KEVEPSS 23%analysed8.2CVE-2024-21893Ivanti Connect Secure SAML SSRF allows unauthenticated resource accessThe SAML component of Ivanti Connect Secure, Policy Secure and Neurons for ZTA contains a server-side request forgery flaw that lets an attacker reac…KEVEPSS 100%analysed

Source: NIST National Vulnerability Database (record CVE-2021-22908), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.