VMware issues critical fixes, CISA orders federal agencies to act immediately (CVE-2022-22972)
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2022-22954 | Server-Side Template Injection RCE in VMware Workspace ONE Access and Identity Manager CVE-2022-22954 is a server-side template injection vulnerability (CWE-94) in VMware Workspace ONE Access and VMware Identity Manager that allows remote code execution on affected appliances. It is triggered when attacker-controlled input is passed into a server-side template engine, allowing injected template directives to be evaluated and executed as code on the server. A successful attacker gains the ability to run arbitrary code on the identity appliance, and CISA notes the flaw has been used in ransomware campaigns, so compromise can serve as an initial foothold for broader enterprise intrusion. Any organization running Workspace ONE Access or Identity Manager, including deployments where the Identity Manager component is bundled into VMware Horizon environments, is potentially affected, though the source data does not specify affected version ranges. The vulnerability was added to CISA's Known Exploited Vulnerabilities catalog on 2022-04-14 with ransomware use confirmed and a required action to apply vendor updates, and EPSS currently assigns it a 100% probability of exploitation within 30 days (100th percentile); no public PoC is known. Do: Apply the patches published in VMware advisory VMSA-2022-0011 (April 2022) to Workspace ONE Access and Identity Manager appliances as required by the CISA KEV listing, prioritizing internet-facing instances, and restrict or remove public exposure until patched. Review appliance and web-server logs for template-injection probes and unexpected processes spawned by the identity service, and investigate any indications of compromise for follow-on ransomware or lateral-movement activity. | 9.8 | 100% | KEV ransomware PoC |
| large≈ tens of thousands of internet-exposed Workspace ONE Access / Identity Manager instances (order-of-magnitude estimate; exact count unknown) | |
| CVE-2022-22960 | Local Privilege Escalation in VMware Workspace ONE Access, Identity Manager and vRA VMware Workspace ONE Access, VMware Identity Manager and vRealize Automation virtual appliances contain a local privilege escalation flaw (CWE-250, execution with unnecessary privileges): support scripts shipped with the appliances have improperly set permissions and run with elevated privileges. An attacker who already has some form of local or shell access to an affected appliance can modify or abuse these scripts to execute code as root (per VMware's advisory), gaining full control of the appliance, its identity/directory data and a platform for persistence and pivoting. Organizations running these VMware identity- and cloud-automation appliances are affected, since the weakness is in the appliance software itself; risk is highest where the appliances are reachable or where this bug is chained with other recently disclosed VMware appliance vulnerabilities. The flaw is known exploited in the wild: it was added to CISA's Known Exploited Vulnerabilities catalog on 2022-04-15, and EPSS assigns a high 35.8% probability of exploitation within 30 days (98th percentile), although no public PoC is known and ransomware use is unconfirmed. Do: Apply the patched appliance releases per VMware's instructions, as required by CISA's KEV listing; until patched, restrict local, shell and management-plane access to Workspace ONE Access, Identity Manager and vRealize Automation appliances, and review them for unexpected root-level activity or modified support scripts. Treat this as actively exploited and prioritize patching alongside the other flaws fixed in the same VMware advisory. | 7.8 | 36% | KEV PoC ×3 |
| largetens of thousands of enterprise appliance deployments worldwide (order of magnitude 10^4) | |
| CVE-2022-22972 +1 in the same advisory: …22973 | VMware Workspace ONE Access, Identity Manager and vRealize Automation contain an authentication bypass vulnerability affecting local domain users. VMware Workspace ONE Access, Identity Manager and vRealize Automation contain an authentication bypass vulnerability affecting local domain users. A malicious actor with network access to the UI may be able to obtain administrative access without the need to authenticate. NVD description · AI analysis pending | 9.8 group max | 56% |
| — |
Full article464 words · extracted from helpnetsecurity.com · click to collapse
VMware has released patches for a privately reported critical vulnerability (CVE-2022-22972) in VMware’s Workspace ONE Access, VMware Identity Manager (vIDM), vRealize Lifecycle Manager, vRealize Automation, and VMware Cloud Foundation products, and is urging administrators to patch or mitigate immediately, because “the ramifications of this vulnerability are serious.”
Simultaneously, the Cybersecurity and Infrastructure Security Agency (CISA) has issued an emergency directive for all federal civilian executive branch agencies, which are ordered to enumerate all instances of affected VMware products and either deploy the updates provided by VMware or remove those instances from agency networks by May 23 (Monday).
About CVE-2022-22972
CVE-2022-22972 is an authentication bypass vulnerability affecting local domain users, which could be exploited by malicious actors with network access to the UI to obtain administrative access without the need to authenticate. It affects VMware Workspace ONE Access, Identity Manager and vRealize.
The patches released by VMware on Wednesday also fix CVE-2022-22973, a local privilege escalation vulnerability in VMware Workspace ONE Access and Identity Manager, which could allow attackers with local access to gain “root” privileges on vulnerable systems.
In a supplemental blog post, VMware notes that while some workarounds for the discovered security holes are available, there are downsides to using them instead of implementing the patches.
“The workaround will make admins unable to log into the Workspace ONE Access console using the local admin account, which may impact your organization’s operations,” the company explained, and noted that the only way to remove the vulnerabilities from one’s environment is to apply the patches.
“Workarounds, while convenient, do not remove the vulnerabilities, and may introduce additional complexities that patching would not,” they added.
No active exploitation – yet!
There are no PoC exploits for CVE-2022-22972 or CVE-2022-22973 and there is no mention of them being exploited by attackers.
However, CISA says that since “threat actors were able to reverse engineer [a previous VMware update that fixed CVE 2022-22954and CVE 2022-22960] and begin exploitation of impacted VMware products that remained unpatched within 48 hours of the update’s release,” the agency “expects threat actors to quickly develop a capability to exploit these newly released vulnerabilities in the same impacted VMware products.”
Consequently, it mandated emergency action from all federal civilian executive branch agencies.
CISA has also released a cybersecurity advisory detailing IoCs, detection signatures, and incident reponse recommendations to help administrators detect and respond to active exploitation of CVE-2022-22954 and CVE-2022-22960.
VMware has noted that by applying the latest product updates (with patches), admins who have not previously implemented fixes for CVE 2022-22954and CVE 2022-22960 will simultaneously get them, as “VMware product updates are cumulative for security.”
Still, that doesn’t mean that their installations haven’t already been compromised by attackers, so they would do well to review CISA’s security advisory and search for evidence of compromise.
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2022/05/19/cve-2022-22972/