CISA urges defenders to update after VMware patches vulnerabilities in multiple products
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2021-44228 | JNDI Injection Remote Code Execution in Apache Log4j2 (Log4Shell) Apache Log4j2, an extremely widely used Java logging library, fails to protect its JNDI lookup feature against attacker-controlled JNDI-related endpoints (CWE-20, CWE-502), so crafted text processed by the logger causes the Java runtime to fetch and load attacker-supplied objects, leading to remote code execution. The flaw is triggered whenever attacker-controlled input reaches the logging API and is parsed for JNDI lookups, a pattern common in web servers and enterprise Java applications that log user-supplied fields such as headers or form values. Successful exploitation yields arbitrary code execution under the privileges of the affected application, giving attackers a foothold for lateral movement, data theft, and ransomware deployment. Any Java application or product that ships or bundles an affected Apache Log4j2 release is exposed, making this one of the most broadly deployed vulnerabilities ever disclosed. Exploitation is confirmed in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2021-12-10 with known ransomware use, and EPSS assigns a 100% probability of exploitation within 30 days. Do: Inventory all Java applications and dependencies for Apache Log4j2 and apply the vendor's patched updates, or remove affected assets from the network, as required by CISA's KEV catalog. Where updates are not yet available, use the temporary mitigations in CISA's ED-22-02 recommended-mitigation guidance, such as disabling message lookups, only until patches are applied. Prioritize internet-facing and business-critical systems and hunt for exploitation activity given known ransomware use. | 10.0 | 100% | KEV ransomware PoC ×9 |
| masshundreds of millions of Java applications/devices, with hundreds of thousands of internet-exposed services | |
| CVE-2022-31656 +1 in the same advisory: …31659 | VMware Workspace ONE Access, Identity Manager and vRealize Automation contain an authentication bypass vulnerability affecting local domain users. VMware Workspace ONE Access, Identity Manager and vRealize Automation contain an authentication bypass vulnerability affecting local domain users. A malicious actor with network access to the UI may be able to obtain administrative access without the need to authenticate. NVD description · AI analysis pending | 9.8 group max | 23% |
| — |
Full article506 words · extracted from therecord.media · click to collapse
The Cybersecurity and Infrastructure Security Agency (CISA) warned of several vulnerabilities recently identified and patched by VMware affecting a variety of the company’s products. VMware released security updates to address multiple vulnerabilities in VMware’s Workspace ONE Access, Access Connector, Identity Manager, Identity Manager Connector, and vRealize Automation. “A remote attacker could exploit some of these vulnerabilities to take control of an affected system,” CISA said. In a release from VMware, the company said the vulnerabilities had CVSS scores ranging from 4.7 to 9.8 — a CVSS score of 10 is used for the most critical vulnerabilities. The issues were discovered by researchers from VNG Security, Rapid7, Qihoo 360 Vulnerability Research Institute and Secura. I have found vulnerabilities CVE-2022-31656 and CVE-2022-31659 leading to unauthenticated remote code execution affecting many #VMware products, such as Workspace ONE. Technical writeup and POC soon to follow. Recommend to patch or mitigate immediately.https://t.co/DnknXFieY3 pic.twitter.com/Uu1LQmb0fQ The most serious vulnerability – CVE-2022-31656 – affects VMware Workspace ONE Access, Identity Manager and vRealize Automation. Tenable senior research engineer Claire Tills told The Record CVE-2022-31656 is particularly concerning as an attacker could use this flaw to bypass authentication and gain administrative access. “This urgency is compounded by the fact that a proof-of-concept is forthcoming from the researcher who discovered the flaw,” Tillis said, noting that the prevalence of attacks targeting VMware vulnerabilities make patching CVE-2022-31656 a priority. “As an authentication bypass, exploitation of this flaw opens up the possibility that attackers could create very troubling exploit chains. In this same release, VMware patched three authenticated flaws that could be paired with CVE-2022-31656 to achieve remote code execution.” The issue is the only in the group of vulnerabilities disclosed that VMware provided a workaround solution for. But VMware noted that the workaround is only a temporary solution and will result in loss of certain functionality, urging users to apply the patches provided. In a blog post for Tenable, Tills noted that CISA published an advisory in May following the release of VMSA-2022-0014 warning of attack chains being leveraged against VMware targets. VMware said it was not aware of active exploitation of any of the vulnerabilities spotlighted in the updates. Today we released a new Critical Severity VMware Security Advisory. Check out https://t.co/pFDndxVwV8. #VMware Bud Broomhead, CEO at security company Viakoo, said the issues would affect a large number of users, noting that VMware Workspace ONE users include the U.S. Senate, Walmart, Verizon, Centene, and many other well-known organizations. In June, CISA warned that unpatched VMware Horizon and Unified Access Gateway (UAG) servers are still being exploited through CVE-2021-44228 – known widely as Log4Shell.
No previous article
No new articles
Jonathan Greig
is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.
Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/cisa-urges-defenders-to-update-after-vmware-patches-vulnerabilities-in-multiple-products