ZeroHour
Security Affairspublished ()ingested @securityaffairs

VMware warns of the availability of CVE-2021

criticalVulnerabilityimportance 60CVE-2021-39144

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2021-39144
Deserialization RCE in XStream XML Library Affecting Multiple Vendors

CVE-2021-39144 is a remote code execution vulnerability in XStream, a widely used Java library that serializes objects to XML and back, caused by unsafe deserialization of a manipulated input stream (CWE-502, CWE-94, CWE-306). An attacker with sufficient rights to feed crafted input into an application running an affected XStream version can trigger arbitrary type instantiation and execute commands on the host, with high impact to confidentiality, integrity and availability (CVSS 3.1: 8.5, scope changed). Only deployments relying on XStream's default blacklist configuration are affected; users who configured XStream's security framework with a whitelist limited to the minimal required types are not affected, and XStream 1.4.18 removed the vulnerable default blacklist behavior. The library is embedded in many downstream products in the data, including Debian Linux and Fedora packages, NetApp SnapManager, and numerous Oracle Communications, Commerce and Retail products, and it was exploited in VMware Cloud Foundation and NSX Manager. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2023-03-10, is being actively exploited in the wild per current headlines, and EPSS assigns a 98.1% probability of exploitation within 30 days.

Do: Upgrade XStream to 1.4.18 or later, or configure its security framework with a whitelist limited to the minimal required types; apply vendor-supplied updates for VMware Cloud Foundation/NSX Manager, Oracle, NetApp, Debian and Fedora per the CISA KEV required action. Prioritize internet-exposed VMware NSX Manager and Cloud Foundation deployments, which are being actively exploited, and audit any applications that pass untrusted XML input into XStream.

8.598% KEV PoC ×2
  • XStream prior to 1.4.18 (default blacklist configuration; whitelist users unaffected)
  • Debian Linux (xstream package)
  • Fedora Project Fedora (xstream package)
  • +9 more
masson the order of 100,000+ deployments (bundled across Oracle, NetApp, VMware, Debian and Fedora product lines)
Full article224 words · extracted from securityaffairs.com · click to collapse

VMware warned of the availability of a public exploit for a recently addressed critical remote code execution flaw in NSX Data Center for vSphere (NSX-V).

VMware warned of the existence of a public exploit targeting a recently addressed critical remote code execution (RCE) vulnerability, tracked as CVE-2021-39144 (CVSS score of 9.8), in NSX Data Center for vSphere (NSX-V).

VMware NSX is a network virtualization solution that is available in VMware vCenter Server.

The remote code execution vulnerability resides in the XStream open-source library. Unauthenticated attackers can exploit the vulnerability in low-complexity attacks without user interaction.

“Due to an unauthenticated endpoint that leverages XStream for input serialization in VMware Cloud Foundation (NSX-V), a malicious actor can get remote code execution in the context of ‘root’ on the appliance.” reads the advisory published by the company.

The product team has also released patches for end-of-life products due to the severity of the vulnerability.

“VMware has confirmed that exploit code leveraging CVE-2021-39144 against impacted products has been published.” reads the advisory published by the virtualization giant.

The virtualization firm also published separate guidance to upgrade NSX-V 6.4.14 appliances on Cloud Foundation 3.x.

The company urges its customers to upgrade their installs to the latest release.

Follow me on Twitter: @securityaffairs and Facebook

[adrotate banner=”9″][adrotate banner=”12″]

Pierluigi Paganini

(SecurityAffairs – hacking, NSX-V)

[adrotate banner=”5″]

[adrotate banner=”13″]



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/137912/security/vmware-cve-2021-39144-exploit.html