Security News > 2022 > May > VMware issues critical fixes, CISA orders federal agencies to act immediately (CVE-2022-22972)
VMware has released patches for a privately reported critical vulnerability in VMware's Workspace ONE Access, VMware Identity Manager, vRealize Lifecycle Manager, vRealize Automation, and VMware Cloud Foundation products, and is urging administrators to patch or mitigate immediately, because "The ramifications of this vulnerability are serious."
Simultaneously, the Cybersecurity and Infrastructure Security Agency has issued an emergency directive for all federal civilian executive branch agencies, which are ordered to enumerate all instances of affected VMware products and either deploy the updates provided by VMware or remove those instances from agency networks by May 23.
The patches released by VMware on Wednesday also fix CVE-2022-22973, a local privilege escalation vulnerability in VMware Workspace ONE Access and Identity Manager, which could allow attackers with local access to gain "Root" privileges on vulnerable systems.
In a supplemental blog post, VMware notes that while some workarounds for the discovered security holes are available, there are downsides to using them instead of implementing the patches.
CISA says that since "Threat actors were able to reverse engineer and begin exploitation of impacted VMware products that remained unpatched within 48 hours of the update's release," the agency "Expects threat actors to quickly develop a capability to exploit these newly released vulnerabilities in the same impacted VMware products."
VMware has noted that by applying the latest product updates, admins who have not previously implemented fixes for CVE 2022-22954and CVE 2022-22960 will simultaneously get them, as "VMware product updates are cumulative for security."
News URL
https://www.helpnetsecurity.com/2022/05/19/cve-2022-22972/
Related news
- CISA: Network switch RCE flaw impacts critical infrastructure (source)
- CISA says critical Fortinet RCE flaw now exploited in attacks (source)
- CISA Warns of Critical Fortinet Flaw as Palo Alto and Cisco Issue Urgent Security Patches (source)
- CISA adds fresh Ivanti vuln, critical Fortinet bug to hall of shame (source)
- VMware Releases vCenter Server Update to Fix Critical RCE Vulnerability (source)
- VMware fixes critical vCenter Server RCE bug – again! (CVE-2024-38812) (source)
- VMware fixes bad patch for critical vCenter Server RCE flaw (source)
- VMware fixes critical RCE, make-me-root bugs in vCenter - for the second time (source)
- Week in review: Fortinet patches critical FortiManager 0-day, VMware fixes vCenter Server RCE (source)
- CISA warns of critical Palo Alto Networks bug exploited in attacks (source)
Related Vulnerability
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2022-05-20 | CVE-2022-22973 | Unspecified vulnerability in VMWare products VMware Workspace ONE Access and Identity Manager contain a privilege escalation vulnerability. | 7.8 |