Chinese Hackers Exploit VMware Zero-Day to Backdoor Windows and Linux Systems
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2023-20867 | Authentication Bypass in VMware Tools Lets Compromised ESXi Hosts Run Guest Operations VMware Tools, the agent installed inside guest virtual machines, fails to properly authenticate host-to-guest operations when they are issued from an ESXi host (CVE-2023-20867, CWE-287 improper authentication). An attacker who has already gained full (root) control of an ESXi host can invoke these operations, such as running commands or moving files inside guest VMs, and the guests' VMware Tools will accept them without valid authentication. This gives an attacker a foothold in guest VMs without guest credentials, affecting guest confidentiality and integrity. Any organization running VMware ESXi/vSphere with VMware Tools in its guests is affected, and the component is also shipped as open-vm-tools in Debian and Fedora. The flaw is confirmed exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2023-06-23 (EPSS 13.5%, 96th percentile), and China-linked APT UNC3886, whose 'Fire Ant' tooling targets ESXi and vCenter, has been reported using it alongside other VMware flaws. Do: Upgrade VMware Tools / open-vm-tools to the latest fixed release distributed by VMware, Debian, or Fedora per the vendor advisory, and inventory guests running outdated Tools. Because exploitation requires a fully compromised ESXi host, hunt for signs of host compromise (unexpected processes, modified VIBs, suspicious vCenter activity) and review guest VMs for unexplained command execution or persistence. Consistent with the KEV required action, prioritize patching, starting with internet-facing ESXi hosts and virtualization management infrastructure. | 3.9 | 14% | KEV |
| mass≈millions of guest VMs (VMware Tools is installed by default on nearly all VMware guests), though actual exploitability requires an already fully compromised… | |
| CVE-2023-20887 | Unauthenticated Command Injection RCE in VMware Aria Operations for Networks VMware Aria Operations for Networks (formerly vRealize Network Insight) contains a command injection flaw (CWE-77) that allows an attacker with network access to the appliance to run arbitrary operating-system commands. Because the attack requires no authentication, privileges, or user interaction (CVSS:3.1/AV:N/AC:L/PR:N/UI:N), any party able to reach the product's network interface can trigger it, gaining remote code execution with high impact on confidentiality, integrity, and availability. Any organization running the product is affected, with internet-facing deployments at the greatest risk. Exploitation is confirmed in the wild — CISA added the flaw to the KEV catalog on 2023-06-22, a public proof-of-concept exploit is available, and EPSS puts the 30-day exploitation probability at 98.3% (top percentile). Ransomware use is currently unknown. Do: Apply the vendor's patched update to all Aria Operations for Networks deployments as soon as possible — this is also CISA's required KEV action (apply updates per vendor instructions); verify the installed build against VMware's advisory for affected ranges. Until patching is complete, restrict network access to the appliance (firewall rules, VPN, or management-segment isolation), prioritizing any instance reachable from the internet since no authentication is required to exploit. Hunt for indicators of command injection exploitation, as in-the-wild exploitation has been confirmed. | 9.8 | 98% | KEV PoC |
| moderate≈10,000+ appliance deployments worldwide (low tens of thousands of appliance nodes); only a small fraction, likely hundreds to low thousands of instances, are… | |
| CVE-2023-20888 +1 in the same advisory: …20889 | Aria Operations for Networks contains an authenticated deserialization vulnerability. Aria Operations for Networks contains an authenticated deserialization vulnerability. A malicious actor with network access to VMware Aria Operations for Networks and valid 'member' role credentials may be able to perform a deserialization attack resulting in remote code execution. NVD description · AI analysis pending | 8.8 group max | 82% |
| — |
Full article441 words · extracted from thehackernews.com · click to collapse
Ravie LakshmananJun 14, 2023Zero-Day / Network Security
The Chinese state-sponsored group known as UNC3886 has been found to exploit a zero-day flaw in VMware ESXi hosts to backdoor Windows and Linux systems.
The VMware Tools authentication bypass vulnerability, tracked as CVE-2023-20867 (CVSS score: 3.9), "enabled the execution of privileged commands across Windows, Linux, and PhotonOS (vCenter) guest VMs without authentication of guest credentials from a compromised ESXi host and no default logging on guest VMs," Mandiant said.
UNC3886 was initially documented by the Google-owned threat intelligence firm in September 2022 as a cyber espionage actor infecting VMware ESXi and vCenter servers with backdoors named VIRTUALPITA and VIRTUALPIE.
Earlier this March, the group was linked to the exploitation of a now-patched medium-severity security flaw in the Fortinet FortiOS operating system to deploy implants on the network appliances and interact with the aforementioned malware.
The threat actor has been described as a "highly adept" adversarial collective targeting defense, technology, and telecommunication organizations in the U.S., Japan, and the Asia-Pacific region.
"The group has access to extensive research and support for understanding the underlying technology of appliances being targeted," Mandiant researchers said, calling out its pattern of weaponizing flaws in firewall and virtualization software that do not support EDR solutions.
As part of its efforts to exploit ESXi systems, the threat actor has also been observed harvesting credentials from vCenter servers as well as abusing CVE-2023-20867 to execute commands and transfer files to and from guest VMs from a compromised ESXi host.
A notable aspect of UNC3886's tradecraft is its use of Virtual Machine Communication Interface (VMCI) sockets for lateral movement and continued persistence, thereby allowing it to establish a covert channel between the ESXi host and its guest VMs.
"This open communication channel between guest and host, where either role can act as client or server, has enabled a new means of persistence to regain access on a backdoored ESXi host as long as a backdoor is deployed and the attacker gains initial access to any guest machine," the company said.
The development comes as Summoning Team researcher Sina Kheirkhah disclosed three different flaws in VMware Aria Operations for Networks (CVE-2023-20887, CVE-2023-20888, and CVE-2023-20889) that could result in remote code execution.
"UNC3886 continues to present challenges to investigators by disabling and tampering with logging services, selectively removing log events related to their activity," it further added. "The threat actors' retroactive cleanup performed within days of past public disclosures on their activity indicates how vigilant they are."
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.
Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2023/06/chinese-hackers-exploit-vmware-zero-day.html