Attackers are exploiting VMware RCE to deliver malware (CVE-2022-22954)
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2022-22954 | Server-Side Template Injection RCE in VMware Workspace ONE Access and Identity Manager CVE-2022-22954 is a server-side template injection vulnerability (CWE-94) in VMware Workspace ONE Access and VMware Identity Manager that allows remote code execution on affected appliances. It is triggered when attacker-controlled input is passed into a server-side template engine, allowing injected template directives to be evaluated and executed as code on the server. A successful attacker gains the ability to run arbitrary code on the identity appliance, and CISA notes the flaw has been used in ransomware campaigns, so compromise can serve as an initial foothold for broader enterprise intrusion. Any organization running Workspace ONE Access or Identity Manager, including deployments where the Identity Manager component is bundled into VMware Horizon environments, is potentially affected, though the source data does not specify affected version ranges. The vulnerability was added to CISA's Known Exploited Vulnerabilities catalog on 2022-04-14 with ransomware use confirmed and a required action to apply vendor updates, and EPSS currently assigns it a 100% probability of exploitation within 30 days (100th percentile); no public PoC is known. Do: Apply the patches published in VMware advisory VMSA-2022-0011 (April 2022) to Workspace ONE Access and Identity Manager appliances as required by the CISA KEV listing, prioritizing internet-facing instances, and restrict or remove public exposure until patched. Review appliance and web-server logs for template-injection probes and unexpected processes spawned by the identity service, and investigate any indications of compromise for follow-on ransomware or lateral-movement activity. | 9.8 | 100% | KEV ransomware PoC |
| large≈ tens of thousands of internet-exposed Workspace ONE Access / Identity Manager instances (order-of-magnitude estimate; exact count unknown) |
Full article244 words · extracted from helpnetsecurity.com · click to collapse
Cyber crooks have begun exploiting CVE-2022-22954, a RCE vulnerability in VMware Workspace ONE Access and Identity Manager, to deliver cryptominers onto vulnerable systems.

About CVE-2022-22954
CVE-2022-22954 is, in effect, a server-side template injection vulnerability that can be triggered by a malicious actor with network access to achieve remote code execution.
It was reported to VMware privately and a fix and a workaround for it was released on April 6, along with fixes for seven other flaws in various VMware solutions.
CVE-2022-22954 is the most critical of the bunch, and VMware urged administrators to patch or mitigate it immediately, as “the ramifications of this vulnerability are serious.”
The warning was echoed earlier this week by NHS Digital, which noted that vulnerabilities in VMware products have been commonly targeted by ATP groups in the past.
“Multiple proof of concept (PoC) codes to exploit CVE-2022-22954 are now being publicly circulated and could be used to replicate the attack against an affected system,” the organization noted. “Due to the trivial nature of the PoC exploits, weaponisation of CVE-2022-22954 is more likely.”
And it came to that soon, as confirmed by Bad Packets and security researcher Daniel Card:
This is being exploited in the wild and crypto miners are being deployed#HUMINT
CVE-2022-22954#Vmware #Workspace VulnerabilitiesExpect #ransomware now/soon https://t.co/WlVy4EF9ZG
— MrR3b00t | #StandWithUkraine #DefendAsOne (@UK_Daniel_Card) April 13, 2022
Admins who haven’t yet implemented the fix or the offered mitigation are advised to get a move on.
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2022/04/14/cve-2022-22954/