Security News > 2020 > April > That critical VMware vuln allowed anyone on your network to create new admin users, no creds needed

That critical VMware vuln allowed anyone on your network to create new admin users, no creds needed
2020-04-17 15:59

A critical vulnerability in VMware's vCenter management product allowed any old bod on the same network to remotely create an admin-level user, research by Guardicore Labs has revealed.

The astonishing vuln, details of which were quite spare when VMWare issued a patch last week, was rated by VMware itself as CVSS v3 10.0, the highest level.

Guardicore researcher JJ Lehman told The Register: "You have to be network accessible but you don't have to be authenticated in any way to pull this off. Which means as an attacker who has already breached the perimeter of a network, as long as [you have] access to the vCenter, you essentially control everything on their VMware hosts."

Curiosity piqued as they examined the vCenter patch binaries, Guardicore's researchers discovered a VMware Github repo called Project Lightning which happened to contain an identical copy of VMware's Directory Service code.

Lehman and Ziv could create a new user account and assign them full admin permissions, all because vCenter did not thoroughly authenticate and cross-check external inputs.


News URL

https://go.theregister.co.uk/feed/www.theregister.co.uk/2020/04/17/vmware_vcenter_critical_vuln_anyone_create_admin_users/

Related vendor

VENDOR LAST 12M #/PRODUCTS LOW MEDIUM HIGH CRITICAL TOTAL VULNS
Vmware 146 11 222 256 102 591