ZeroHour
The Recordpublished ()ingested

CISA issues directive for exploited VMware bug after IR team deployed to ‘large’ org

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2022-22954
Server-Side Template Injection RCE in VMware Workspace ONE Access and Identity Manager

CVE-2022-22954 is a server-side template injection vulnerability (CWE-94) in VMware Workspace ONE Access and VMware Identity Manager that allows remote code execution on affected appliances. It is triggered when attacker-controlled input is passed into a server-side template engine, allowing injected template directives to be evaluated and executed as code on the server. A successful attacker gains the ability to run arbitrary code on the identity appliance, and CISA notes the flaw has been used in ransomware campaigns, so compromise can serve as an initial foothold for broader enterprise intrusion. Any organization running Workspace ONE Access or Identity Manager, including deployments where the Identity Manager component is bundled into VMware Horizon environments, is potentially affected, though the source data does not specify affected version ranges. The vulnerability was added to CISA's Known Exploited Vulnerabilities catalog on 2022-04-14 with ransomware use confirmed and a required action to apply vendor updates, and EPSS currently assigns it a 100% probability of exploitation within 30 days (100th percentile); no public PoC is known.

Do: Apply the patches published in VMware advisory VMSA-2022-0011 (April 2022) to Workspace ONE Access and Identity Manager appliances as required by the CISA KEV listing, prioritizing internet-facing instances, and restrict or remove public exposure until patched. Review appliance and web-server logs for template-injection probes and unexpected processes spawned by the identity service, and investigate any indications of compromise for follow-on ransomware or lateral-movement activity.

9.8100% KEV ransomware PoC
  • VMware Workspace ONE Access
  • VMware Identity Manager
large≈ tens of thousands of internet-exposed Workspace ONE Access / Identity Manager instances (order-of-magnitude estimate; exact count unknown)
CVE-2022-22960
Local Privilege Escalation in VMware Workspace ONE Access, Identity Manager and vRA

VMware Workspace ONE Access, VMware Identity Manager and vRealize Automation virtual appliances contain a local privilege escalation flaw (CWE-250, execution with unnecessary privileges): support scripts shipped with the appliances have improperly set permissions and run with elevated privileges. An attacker who already has some form of local or shell access to an affected appliance can modify or abuse these scripts to execute code as root (per VMware's advisory), gaining full control of the appliance, its identity/directory data and a platform for persistence and pivoting. Organizations running these VMware identity- and cloud-automation appliances are affected, since the weakness is in the appliance software itself; risk is highest where the appliances are reachable or where this bug is chained with other recently disclosed VMware appliance vulnerabilities. The flaw is known exploited in the wild: it was added to CISA's Known Exploited Vulnerabilities catalog on 2022-04-15, and EPSS assigns a high 35.8% probability of exploitation within 30 days (98th percentile), although no public PoC is known and ransomware use is unconfirmed.

Do: Apply the patched appliance releases per VMware's instructions, as required by CISA's KEV listing; until patched, restrict local, shell and management-plane access to Workspace ONE Access, Identity Manager and vRealize Automation appliances, and review them for unexpected root-level activity or modified support scripts. Treat this as actively exploited and prioritize patching alongside the other flaws fixed in the same VMware advisory.

7.836% KEV PoC ×3
  • VMware Workspace ONE Access
  • VMware Identity Manager
  • VMware vRealize Automation
largetens of thousands of enterprise appliance deployments worldwide (order of magnitude 10^4)
CVE-2022-22972
+1 in the same advisory: …22973
VMware Workspace ONE Access, Identity Manager and vRealize Automation contain an authentication bypass vulnerability affecting local domain users.

VMware Workspace ONE Access, Identity Manager and vRealize Automation contain an authentication bypass vulnerability affecting local domain users. A malicious actor with network access to the UI may be able to obtain administrative access without the need to authenticate.

NVD description · AI analysis pending
9.8
group max
56%
  • vmware identity manager
  • vmware vrealize automation
  • vmware workspace one access
  • +1 more
Full article810 words · extracted from therecord.media · click to collapse

The Cybersecurity and Infrastructure Security Agency (CISA) issued an emergency directive on Wednesday ordering federal civilian agencies to patch critical vulnerabilities in VMware products.

CISA said it released the notice after deploying an incident response team “to a large organization where the threat actors exploited CVE-2022-22954” — the name given to a recently-discovered remote code execution vulnerability.

“Additionally, CISA has received information—including indicators of compromise (IOCs)—about observed exploitation at multiple other large organizations from trusted third parties,” CISA explained

Since April, cybersecurity experts have warned that state-backed actors are exploiting the bugs – CVE 2022-22954 and CVE 2022-22960 – which affect widely-used products: VMware Workspace ONE Access (Access), VMware Identity Manager (vIDM), VMware vRealize Automation (vRA), VMware Cloud Foundation, and vRealize Suite Lifecycle Manager.

We issued Emergency Directive 22-03 in response to observed or expected active exploitation of a series of vulnerabilities in specific VMware products. Federal civilian agencies need to take specific actions to protect their networks today: https://t.co/wyHkKez91U pic.twitter.com/PJfb4iEQtP

— Cybersecurity and Infrastructure Security Agency (@CISAgov) May 18, 2022

In the emergency directive, CISA said VMware released updates for the issues on April 6, but hackers managed to reverse engineer the update and begin exploitation of VMware products that were unpatched within 48 hours of the update’s release.

“CISA has determined that these vulnerabilities pose an unacceptable risk to Federal Civilian Executive Branch (FCEB) agencies and require emergency action,” CISA explained. 

The agency noted that they expect hackers to “quickly develop a capability to exploit newly released vulnerabilities CVE-2022-22972 and CVE-2022-22973 in the same impacted VMware products.”

Threat actors are chaining the vulnerabilities together during attacks, according to third party reports sent to CISA. 

“At one compromised organization, on or around April 12, 2022, an unauthenticated actor with network access to the web interface leveraged CVE-2022-22954 to execute an arbitrary shell command as a VMware user,” the agency explained. 

“The actor then exploited CVE-2022-22960 to escalate the user’s privileges to root. With root access, the actor could wipe logs, escalate permissions, and move laterally to other systems.”

Another incident spotted by CISA on April 13 found hackers using CVE-2022-22954 to drop the Dingo J-spy webshell. Webshells are malicious scripts that enable threat actors to compromise web servers and launch additional attacks.

CISA noted that other cybersecurity entities have seen attackers use the Dingo J-spy webshell. The agency said it will release further updates as it analyzes the malware. 

— mRr3b00t (@UK_Daniel_Card) April 13, 2022

CISA said it has confirmed that CVE-2022-22954 and CVE-2022-22960 have been exploited in the wild and published the emergency directive because of “the likelihood of future exploitation” as well as “the prevalence of the affected software in the federal enterprise, and the high potential for a compromise of agency information systems.”

Federal civilian agencies are required to comply with the directive alongside “systems used or operated by another entity on behalf of an agency, that collects, processes, stores, transmits, disseminates, or otherwise maintains agency information, for the purpose of protecting the information system from, or mitigating, an information security threat.”

The latest updates issued by VMware must now be implemented by 5 pm on May 23. CISA noted that any instances of impacted VMware products that were accessible from the internet should be assumed to be compromised. 

The agency ordered directors to immediately disconnect the products from the production network and contact them. Networks will only be reconnected “after threat hunt activities are complete with no anomalies detected and updates are applied.”

By May 24, all agencies need to report to CISA about their investigation of the issue. 

Barracuda's Mike Goldgof told The Record that abuse of CVE-2022-22954 would allow a hacker to bring down a system, extract data, inject ransomware, and more.

Tushar Richabadas, lead researcher for Barracuda, said the vulnerability "has been added to the regular rotation of vulnerabilities that are scanned for by threat actors."

"Given how damaging it can be if a VMware installation is exploited by this vulnerability, we’ll see low levels of continual scanning for this vulnerability for quite some time, similar to other VMware vulnerabilities from last year," Richabadas said.

"Any vulnerable VMware installation that can be exploited to be used as part of a DDoS botnet, implanted with a coin miner or used to stage deeper incursions into the network hosting the exploited application. I would not be surprised if these are used to spread ransomware infections into exploited networks – we did see attempts at that with Log4Shell, per Microsoft back in January, with an earlier VMware vulnerability."

No previous article

No new articles

Jonathan Greig

is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.

Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/cisa-issues-directive-for-exploited-vmware-bug-after-ir-team-deployed-to-large-org