Security News > 2022 > May > Researchers to release exploit for new VMware auth bypass, patch now

Researchers to release exploit for new VMware auth bypass, patch now
2022-05-24 14:16

Proof-of-concept exploit code is about to be published for a vulnerability that allows administrative access without authentication in several VMware products.

Security researchers at attack surface assessment company Horizon3 announced today that they managed to create a working proof-of-concept exploit code for CVE-2022-22972 and will be releasing a technical report shortly.

The severity of the vulnerability has been further highlighted by the U.S. Cybersecurity and Infrastructure Security Agency in an emergency directive published on the same day VMware released the fix for CVE-2022-22972.

A set of critical vulnerabilities that VMware patched in April started to be exploited in the wild just 48 hours after the company released an alert and the corresponding fixes, to install cryptocurrency miners and backdoors.

Horizon3 previously released exploit code for CVE-2022-1388 - a critical vulnerability that allows remote code execution in F5 BIG-IP networking devices.

Just like with the upcoming exploit release for the VMware vulnerability, the researchers strongly recommended admins to patch their vulnerable F5 appliances.


News URL

https://www.bleepingcomputer.com/news/security/researchers-to-release-exploit-for-new-vmware-auth-bypass-patch-now/

Related Vulnerability

DATE CVE VULNERABILITY TITLE RISK
2022-05-20 CVE-2022-22972 Unspecified vulnerability in VMWare products
VMware Workspace ONE Access, Identity Manager and vRealize Automation contain an authentication bypass vulnerability affecting local domain users.
network
low complexity
vmware
critical
9.8
2022-05-05 CVE-2022-1388 Missing Authentication for Critical Function vulnerability in F5 products
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13.1.5, and all 12.1.x and 11.6.x versions, undisclosed requests may bypass iControl REST authentication.
network
low complexity
f5 CWE-306
critical
9.8

Related vendor

VENDOR LAST 12M #/PRODUCTS LOW MEDIUM HIGH CRITICAL TOTAL VULNS
Vmware 186 84 404 199 101 788