CISA Issues Emergency Directive for VMware Vulnerabilities
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2022-22954 | Server-Side Template Injection RCE in VMware Workspace ONE Access and Identity Manager CVE-2022-22954 is a server-side template injection vulnerability (CWE-94) in VMware Workspace ONE Access and VMware Identity Manager that allows remote code execution on affected appliances. It is triggered when attacker-controlled input is passed into a server-side template engine, allowing injected template directives to be evaluated and executed as code on the server. A successful attacker gains the ability to run arbitrary code on the identity appliance, and CISA notes the flaw has been used in ransomware campaigns, so compromise can serve as an initial foothold for broader enterprise intrusion. Any organization running Workspace ONE Access or Identity Manager, including deployments where the Identity Manager component is bundled into VMware Horizon environments, is potentially affected, though the source data does not specify affected version ranges. The vulnerability was added to CISA's Known Exploited Vulnerabilities catalog on 2022-04-14 with ransomware use confirmed and a required action to apply vendor updates, and EPSS currently assigns it a 100% probability of exploitation within 30 days (100th percentile); no public PoC is known. Do: Apply the patches published in VMware advisory VMSA-2022-0011 (April 2022) to Workspace ONE Access and Identity Manager appliances as required by the CISA KEV listing, prioritizing internet-facing instances, and restrict or remove public exposure until patched. Review appliance and web-server logs for template-injection probes and unexpected processes spawned by the identity service, and investigate any indications of compromise for follow-on ransomware or lateral-movement activity. | 9.8 | 100% | KEV ransomware PoC |
| large≈ tens of thousands of internet-exposed Workspace ONE Access / Identity Manager instances (order-of-magnitude estimate; exact count unknown) | |
| CVE-2022-22960 | Local Privilege Escalation in VMware Workspace ONE Access, Identity Manager and vRA VMware Workspace ONE Access, VMware Identity Manager and vRealize Automation virtual appliances contain a local privilege escalation flaw (CWE-250, execution with unnecessary privileges): support scripts shipped with the appliances have improperly set permissions and run with elevated privileges. An attacker who already has some form of local or shell access to an affected appliance can modify or abuse these scripts to execute code as root (per VMware's advisory), gaining full control of the appliance, its identity/directory data and a platform for persistence and pivoting. Organizations running these VMware identity- and cloud-automation appliances are affected, since the weakness is in the appliance software itself; risk is highest where the appliances are reachable or where this bug is chained with other recently disclosed VMware appliance vulnerabilities. The flaw is known exploited in the wild: it was added to CISA's Known Exploited Vulnerabilities catalog on 2022-04-15, and EPSS assigns a high 35.8% probability of exploitation within 30 days (98th percentile), although no public PoC is known and ransomware use is unconfirmed. Do: Apply the patched appliance releases per VMware's instructions, as required by CISA's KEV listing; until patched, restrict local, shell and management-plane access to Workspace ONE Access, Identity Manager and vRealize Automation appliances, and review them for unexpected root-level activity or modified support scripts. Treat this as actively exploited and prioritize patching alongside the other flaws fixed in the same VMware advisory. | 7.8 | 36% | KEV PoC ×3 |
| largetens of thousands of enterprise appliance deployments worldwide (order of magnitude 10^4) | |
| CVE-2022-22972 +1 in the same advisory: …22973 | VMware Workspace ONE Access, Identity Manager and vRealize Automation contain an authentication bypass vulnerability affecting local domain users. VMware Workspace ONE Access, Identity Manager and vRealize Automation contain an authentication bypass vulnerability affecting local domain users. A malicious actor with network access to the UI may be able to obtain administrative access without the need to authenticate. NVD description · AI analysis pending | 9.8 group max | 56% |
| — |
Full article428 words · extracted from infosecurity-magazine.com · click to collapse
The Cybersecurity and Infrastructure Security Agency (CISA) has issued an emergency directive to all federal agencies to mitigate two new VMware vulnerabilities.
The directive relates to two new vulnerabilities – CVE-2022-22972 and CVE-2022-22973 – that CISA believes threat actors are likely to exploit across numerous VMware products. These are VMware Workspace ONE Access (Access), VMware Identity Manager (vIDM), VMware vRealize Automation (vRA), VMware Cloud Foundation and vRealize Suite Lifecycle Manager.
This follows the significant exploitation of two earlier vulnerabilities in these VMware products, CVE 2022-22954 and CVE 2022-22960, discovered in April. While VMware released an update to patch these vulnerabilities on April 6 2022, threat actors were able to reverse engineer the update and begin the exploitation of impacted VMware products that remained unpatched within 48 hours of the update’s release.
CISA is concerned that threat actors will quickly develop the capability to exploit CVE-2022-22972 and CVE-2022-22973 in the same way. This includes via remote code execution, escalating privileges to ‘root’ and obtaining administrative access without the need to authenticate. VMware released an update for these two vulnerabilities yesterday (May 18).
The directive stated: “CISA has determined that these vulnerabilities pose an unacceptable risk to Federal Civilian Executive Branch (FCEB) agencies and require emergency action. This determination is based on the confirmed exploitation of CVE-2022-22954 and CVE-2022-22960 by threat actors in the wild, the likelihood of future exploitation of CVE-2022-22972 and CVE-2022-22973, the prevalence of the affected software in the federal enterprise, and the high potential for a compromise of agency information systems.”
CISA has given all FCEB agencies a deadline of Monday, May 23 2022, to mitigate these issues. They are required to:
- Enumerate all instances of impacted VMware products on agency networks
- Deploy the WMware updates for the vulnerabilities or remove VMware products from the agency network until the update can be applied
In cases where updates are not available due to products being unsupported by the vendor, they must be immediately removed from the agency network.
In addition, for all instances of impacted VMware products that are accessible from the internet, FECB agencies must:
- Assume compromise, immediately disconnect from the production network and conduct threat hunt activities
- Immediately report any anomalies detected to CISA at [email protected] CISA emphasized that the above actions apply to agency assets in information systems used or operated in third-party environments.
Earlier this week, CISA, alongside the cybersecurity authorities of Canada, New Zealand, the Netherlands and the UK, outlined 10 of the most common ways threat actors compromise their victims, most of which can be mitigated by basic cyber-hygiene best practices.
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/cisa-emergency-directive-vmware/