ZeroHour
Infosecurity Magazinepublished ()ingested Phil Muncaster

NSA: Patch VMware Bug Now to Stop Russian Hackers

criticalVulnerabilityimportance 60CVE-2020-4006

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2020-4006
Command Injection in VMware Workspace ONE Access and Identity Manager

CVE-2020-4006 is a command injection flaw (CWE-78, CVSS 3.1 9.1) in the admin consoles of VMware Workspace ONE Access, Workspace ONE Access Connector, VMware Identity Manager, and VMware Identity Manager Connector, with the affected components also shipped inside VMware Cloud Foundation and vRealize Suite Lifecycle Manager. An attacker who gains privileged access to an admin console, which is typically reachable over the network, can inject and run arbitrary commands on the appliance, achieving full compromise of the host with high confidentiality, integrity, and availability impact and a changed scope. Organizations running the affected identity products are exposed, especially where the admin console is internet-facing or reachable from untrusted networks. The bug was actively exploited by Russian state-sponsored (SVR/APT29) actors against unpatched deployments, prompting a CISA emergency directive, NSA and FBI joint warnings, and inclusion in the KEV catalog; EPSS estimates a 17.3% probability of exploitation within 30 days, and no public proof-of-concept is known.

Do: Apply the patches VMware released in its November 2020 advisory (VMSA-2020-0027) for all affected products, connectors, and any Cloud Foundation or vRealize Suite Lifecycle Manager deployments that embed the components — this is a KEV-required action. As an interim mitigation, restrict network access to the admin console (typically port 8443) to trusted users and networks only. Review admin-console and system logs for signs of command injection or SVR/APT29 activity, since the bug was exploited in the wild by Russian state-sponsored actors.

9.117% KEV
  • VMware Workspace ONE Access multiple affected releases (3.x/20.x lines) — see VMware security advisory
  • VMware Workspace ONE Access Connector multiple affected releases (3.x/20.x lines) — see VMware security advisory
  • VMware Identity Manager multiple affected releases (3.x/20.x lines) — see VMware security advisory
  • +3 more
largetens of thousands of enterprise identity-appliance deployments, with likely several thousand admin consoles internet-exposed
Full article343 words · extracted from infosecurity-magazine.com · click to collapse

The National Security Agency (NSA) has issued an alert warning that Russian state hackers are exploiting a VMware vulnerability to access sensitive data and maintain persistence in targeted systems.

The NSA urged network administrators at the US National Security System (NSS), Department of Defense (DoD) and Defense Industrial Base (DIB) to patch the bug as a priority.

VMware fixed CVE-2020-4006 on December 3. It’s a Command Injection Vulnerability that exists in VMware Access and VMware Identity Manager products.

“The exploitation via command injection led to installation of a web shell and follow-on malicious activity where credentials in the form of SAML authentication assertions were generated and sent to Microsoft Active Directory Federation Services (ADFS), which in turn granted the actors access to protected data,” the NSA explained in its advisory.

“It is critical when running products that perform authentication that the server and all the services that depend on it are properly configured for secure operation and integration. Otherwise, SAML assertions could be forged, granting access to numerous resources.”

The NSA recommended that any admins integrating authentication servers with ADFS follow Microsoft best practices such as MFA.

It said that password-based access to the web-based user interface of the device is required to exploit the bug, so using a strong and unique password would help to mitigate the risk, as would disconnecting the interface from the internet.

Daniel Trauner, director of security at Axonius, likened the vulnerability to one in a MobileIron MDM exploited recently as it enables compromise across a potentially large number of organizations.

“Bugs that affect central infrastructure like this, even slightly lower severity bugs that require prerequisites for authentication, are attractive and useful to adversaries because these systems are the central aggregation point for a significant portion of infrastructure. This makes pivoting easy,” he said.

“In addition to prioritizing patching and updating assets with known critical vulnerabilities, organizations need to make sure they are gathering detailed information about their assets —particularly those central to core infrastructure — and continually validate every asset’s adherence to their overall security policy.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/nsa-patch-vmware-bug-stop-russian/