CISA orders federal agencies to fix VMware flaws by May 23, 2022
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2022-22954 | Server-Side Template Injection RCE in VMware Workspace ONE Access and Identity Manager CVE-2022-22954 is a server-side template injection vulnerability (CWE-94) in VMware Workspace ONE Access and VMware Identity Manager that allows remote code execution on affected appliances. It is triggered when attacker-controlled input is passed into a server-side template engine, allowing injected template directives to be evaluated and executed as code on the server. A successful attacker gains the ability to run arbitrary code on the identity appliance, and CISA notes the flaw has been used in ransomware campaigns, so compromise can serve as an initial foothold for broader enterprise intrusion. Any organization running Workspace ONE Access or Identity Manager, including deployments where the Identity Manager component is bundled into VMware Horizon environments, is potentially affected, though the source data does not specify affected version ranges. The vulnerability was added to CISA's Known Exploited Vulnerabilities catalog on 2022-04-14 with ransomware use confirmed and a required action to apply vendor updates, and EPSS currently assigns it a 100% probability of exploitation within 30 days (100th percentile); no public PoC is known. Do: Apply the patches published in VMware advisory VMSA-2022-0011 (April 2022) to Workspace ONE Access and Identity Manager appliances as required by the CISA KEV listing, prioritizing internet-facing instances, and restrict or remove public exposure until patched. Review appliance and web-server logs for template-injection probes and unexpected processes spawned by the identity service, and investigate any indications of compromise for follow-on ransomware or lateral-movement activity. | 9.8 | 100% | KEV ransomware PoC |
| large≈ tens of thousands of internet-exposed Workspace ONE Access / Identity Manager instances (order-of-magnitude estimate; exact count unknown) | |
| CVE-2022-22960 | Local Privilege Escalation in VMware Workspace ONE Access, Identity Manager and vRA VMware Workspace ONE Access, VMware Identity Manager and vRealize Automation virtual appliances contain a local privilege escalation flaw (CWE-250, execution with unnecessary privileges): support scripts shipped with the appliances have improperly set permissions and run with elevated privileges. An attacker who already has some form of local or shell access to an affected appliance can modify or abuse these scripts to execute code as root (per VMware's advisory), gaining full control of the appliance, its identity/directory data and a platform for persistence and pivoting. Organizations running these VMware identity- and cloud-automation appliances are affected, since the weakness is in the appliance software itself; risk is highest where the appliances are reachable or where this bug is chained with other recently disclosed VMware appliance vulnerabilities. The flaw is known exploited in the wild: it was added to CISA's Known Exploited Vulnerabilities catalog on 2022-04-15, and EPSS assigns a high 35.8% probability of exploitation within 30 days (98th percentile), although no public PoC is known and ransomware use is unconfirmed. Do: Apply the patched appliance releases per VMware's instructions, as required by CISA's KEV listing; until patched, restrict local, shell and management-plane access to Workspace ONE Access, Identity Manager and vRealize Automation appliances, and review them for unexpected root-level activity or modified support scripts. Treat this as actively exploited and prioritize patching alongside the other flaws fixed in the same VMware advisory. | 7.8 | 36% | KEV PoC ×3 |
| largetens of thousands of enterprise appliance deployments worldwide (order of magnitude 10^4) | |
| CVE-2022-22972 +1 in the same advisory: …22973 | VMware Workspace ONE Access, Identity Manager and vRealize Automation contain an authentication bypass vulnerability affecting local domain users. VMware Workspace ONE Access, Identity Manager and vRealize Automation contain an authentication bypass vulnerability affecting local domain users. A malicious actor with network access to the UI may be able to obtain administrative access without the need to authenticate. NVD description · AI analysis pending | 9.8 group max | 56% |
| — |
Full article432 words · extracted from securityaffairs.com · click to collapse

CISA orders federal agencies to fix VMware CVE-2022-22972 and CVE-2022-22973 vulnerabilities by May 23, 2022.
The Cybersecurity and Infrastructure Security Agency (CISA) issued the Emergency Directive 22-03 to order federal agencies to fix VMware CVE-2022-22972 and CVE-2022-22973 flaws or to remove the affected products from their networks by May 23, 2022.
The list of impacted products includes:
- VMware Workspace ONE Access (Access)
- VMware Identity Manager (vIDM)
- VMware vRealize Automation (vRA)
- VMware Cloud Foundation
- vRealize Suite Lifecycle Manager
The series of vulnerabilities are CVE 2022-22954, CVE 2022-22960, CVE-2022-22972, CVE-2022-22973; read @CISAgov’s cybersecurity advisory for vulnerable VMware products along with detection and mitigation recommendations: https://t.co/BKsE7OmSai https://t.co/sxoaZ1UYlo
— Follow CISA's accounts: @CISAgov and @CISACyber (@cyber) May 18, 2022
The virtualization giant warns that a threat actor can exploit the flaw, tracked as CVE-2022-22972 (CVSSv3 base score of 9.8), to obtain admin privileges and urges customers to install patches immediately.
“This critical vulnerability should be patched or mitigated immediately per the instructions in VMSA-2021-0014. The ramifications of this vulnerability are serious.” states VMware.
The CVE-2022-22972 flaw affects Workspace ONE Access, VMware Identity Manager (vIDM), and vRealize Automation.
The second issue, is a high severity local privilege escalation security vulnerability, tracked as CVE-2022-22973 (CVSSv3 base score of 7.8) affecting Workspace ONE Access and Identity Manager. The vulnerability can be exploited by an attacker to elevate permissions to ‘root.’
The US agencies believe that threat actors could attempt to exploit the flaws now that both have been disclosed.
“On May 18, 2022, VMware released an update for two new vulnerabilities (CVE-2022-22972 and CVE-2022-22973). Based on the above, CISA expects threat actors to quickly develop a capability to exploit these newly released vulnerabilities in the same impacted VMware products.” reads the security advisory published by CISA. “This determination is based on the confirmed exploitation of CVE-2022-22954 and CVE-2022-22960 by threat actors in the wild, the likelihood of future exploitation of CVE-2022-22972 and CVE-2022-22973, the prevalence of the affected software in the federal enterprise, and the high potential for a compromise of agency information systems.”
DHS also orders federal agencies to report the status of all VMware installs on their networks into Cyberscope by May 24, 2022.
Please vote for Security Affairs as the best European Cybersecurity Blogger Awards 2022 – VOTE FOR YOUR WINNERS
Vote for me in the sections “The Underdogs – Best Personal (non-commercial) Security Blog” and “The Tech Whizz – Best Technical Blog” and others of your choice.
To nominate, please visit: https://docs.google.com/forms/d/e/1FAIpQLSfxxrxICiMZ9QM9iiPuMQIC-IoM-NpQMOsFZnJXrBQRYJGCOw/viewform
Follow me on Twitter: @securityaffairs and Facebook
| [adrotate banner=”9″] | [adrotate banner=”12″] |
(SecurityAffairs – hacking, CISA)
[adrotate banner=”5″]
[adrotate banner=”13″]
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/131436/security/cisa-orders-federal-agencies-to-vmware-flaws.html