Security News > 2022 > November > VMware warns of three critical holes in remote-control tool

VMware warns of three critical holes in remote-control tool
2022-11-09 01:16

VMware has revealed a terrible trio of critical-rated flaws in Workspace ONE Assist for Windows - a product used by IT and help desk staff to remotely take over and manage employees' devices.

A miscreant able to reach a Workspace ONE Assist deployment, either over the internet or on the network, can exploit any of these three bugs to obtain administrative access without the need to authenticate.

It's all possible because Workspace ONE Assist's authentication code appears to be - let's not sugar coat this - borked.

There's more! Workspace ONE Assist is also afflicted with a 6.4-rated cross-site scripting vulnerability that - thanks to improper user input sanitization - can be exploited, with some user interaction, to inject and run malicious JavaScript code in the victim's window.

These flaws apply to versions 21.x and 22.x of Workspace ONE Assist.

In happier news for Virtzilla, the company has announced that its cloudy wares are now available through HPE's GreenLake ITaaS platform, plus - irony alert - a "More secure" version of its Anywhere Workspace hybrid work suite.


News URL

https://go.theregister.com/feed/www.theregister.com/2022/11/09/vmware_workspace_one_assist_critical_flaws/

Related vendor

VENDOR LAST 12M #/PRODUCTS LOW MEDIUM HIGH CRITICAL TOTAL VULNS
Vmware 146 11 222 256 102 591