Security News > 2021 > May > VMware Patches Critical Flaw Reported by Sanctioned Russian Security Firm
VMware has patched another critical vulnerability reported by Positive Technologies, a Russian cybersecurity firm that was sanctioned recently by the United States.
Positive Technologies is one of the several Russian tech firms sanctioned in April by the U.S. for allegedly supporting Kremlin intelligence agencies.
The company has reported many serious vulnerabilities to major vendors such as Microsoft, Intel and VMware over the past years and says that it plans to continue doing so.
The latest security hole reported by Positive Technologies to VMware is CVE-2021-21984, a critical remote code execution vulnerability affecting VMware vRealize Business for Cloud.
Egor Dimitrenko, the Positive Technologies researcher who reported the flaw to VMware, told SecurityWeek that the impacted product is typically used within an organization's local network, but claims that his company has seen instances where these systems have been configured in a way that makes them accessible from the internet.
"Positive Technologies has spent nearly two decades building a stellar reputation in this critical field, and we won't stop now," said a company spokesperson.
News URL
Related news
- Two simple give-me-control security bugs found in Optigo network switches used in critical manufacturing (source)
- CISA Warns of Critical Fortinet Flaw as Palo Alto and Cisco Issue Urgent Security Patches (source)
- VMware Releases vCenter Server Update to Fix Critical RCE Vulnerability (source)
- VMware fixes critical vCenter Server RCE bug – again! (CVE-2024-38812) (source)
- VMware fixes bad patch for critical vCenter Server RCE flaw (source)
- VMware fixes critical RCE, make-me-root bugs in vCenter - for the second time (source)
- Week in review: Fortinet patches critical FortiManager 0-day, VMware fixes vCenter Server RCE (source)
- HPE Issues Critical Security Patches for Aruba Access Point Vulnerabilities (source)
- Major security audit of critical FreeBSD components now available (source)
- Critical RCE bug in VMware vCenter Server now exploited in attacks (source)
Related Vulnerability
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2021-05-07 | CVE-2021-21984 | Missing Authorization vulnerability in VMWare Vrealize Business for Cloud 7.0 VMware vRealize Business for Cloud 7.x prior to 7.6.0 contains a remote code execution vulnerability due to an unauthorised end point. | 9.8 |