• Login
Whats Current In
No Result
View All Result
  • Blockchain
  • Cyber Security
  • Gadgets & Hardware
  • Startups
    • Angel investing
    • Venture Capital
  • More Tech News
    • AI
    • App Development
    • Cloud & SaaS
    • Gaming
    • Web Development
  • Blockchain
  • Cyber Security
  • Gadgets & Hardware
  • Startups
    • Angel investing
    • Venture Capital
  • More Tech News
    • AI
    • App Development
    • Cloud & SaaS
    • Gaming
    • Web Development
No Result
View All Result
Whats Current In
No Result
View All Result
Home Cyber Security

VMware fixes vRealize bug that let attackers run code as root

Sergiu Gatlan by Sergiu Gatlan
April 20, 2023
Reading Time: 2 mins read
0
VMware fixes vRealize bug that let attackers run code as root

VMware

RELATED POSTS

Online sellers targeted by new information-stealing malware campaign

Zyxel shares tips on protecting firewalls from ongoing attacks

Microsoft is killing Cortana on Windows starting late 2023

VMware addressed a critical vRealize Log Insight security vulnerability that allows remote attackers to gain remote execution on vulnerable appliances.

Now known as VMware Aria Operations for Logs, this log analysis tool helps manage terabytes worth of application and infrastructure logs in large-scale environments.

The bug (tracked as CVE-2023-20864) is described as a deserialization vulnerability that can be abused to run arbitrary code as root on compromised systems.

CVE-2023-20864 can be exploited remotely by unauthenticated threat actors in low-complexity attacks that don’t require user interaction.

Today, VMware also released security updates for a second security flaw (tracked as CVE-2023-20865) that enables remote attackers with administrative privileges to execute arbitrary commands as root.

Both vulnerabilities were addressed with the release of VMware Aria Operations for Logs 8.12. There is no evidence that these security bugs were exploited in the wild before being patched.

Buy JNews
ADVERTISEMENT

“CVE-2023-20864 is a critical issue and should be patched immediately as per the instructions in the advisory. It needs to be highlighted that only version 8.10.2 is impacted by this vulnerability (CVE-2023-20864),” VMware said.

“Other versions VMware Aria Operations for Logs (formerly vRealize Log Insight) are impacted by CVE-2023-20865 but this has a lower CVSSv3 score of 7.2.”

Two other critical vRealize bugs patched in January

In January, the company addressed another pair of critical vulnerabilities (CVE-2022-31706 and CVE-2022-31704) affecting the same product and allowing remote code execution, as well as flaws that could be exploited for information theft (CVE-2022-31711) and denial of service attacks (CVE-2022-31710).

One week later, security researchers with Horizon3’s Attack Team released proof-of-concept (PoC) code to chain three of the four bugs to help attackers execute code remotely as root on compromised VMware vRealize appliances.

While just a few dozen VMware vRealize instances are exposed online, this is to be expected since such appliances are designed only to be accessed from inside organizations’ networks.

However, it’s not uncommon for attackers to exploit vulnerabilities affecting devices in already compromised networks, making properly configured yet vulnerable VMware appliances valuable internal targets.

Share54Tweet34Pin12
Sergiu Gatlan

Sergiu Gatlan

Related Posts

Beware: Hackers now use OneNote attachments to spread malware
Cyber Security

Online sellers targeted by new information-stealing malware campaign

June 3, 2023
Zyxel warns of critical vulnerabilities in firewall and VPN devices
Cyber Security

Zyxel shares tips on protecting firewalls from ongoing attacks

June 3, 2023
Microsoft is killing Cortana on Windows starting late 2023
Cyber Security

Microsoft is killing Cortana on Windows starting late 2023

June 2, 2023
Hackers use new, fake crypto app to breach networks, steal cryptocurrency
Cyber Security

The Week in Ransomware – June 2nd 2023 – Whodunit?

June 2, 2023
Microsoft fixes Windows 11 22H2 file copy performance hit
Cyber Security

Windows 11 to require SMB signing to prevent NTLM relay attacks

June 2, 2023
FBI warns of spike in ‘pig butchering’ crypto investment schemes
Cyber Security

NSA and FBI: Kimsuky hackers pose as journalists to steal intel

June 2, 2023

Recommended Stories

Are you Investing in Safemoon? Here’s what you need to know

Are you Investing in Safemoon? Here’s what you need to know

May 1, 2023
Problems galore for DeFi ecosystem as another protocol gets compromised

Problems galore for DeFi ecosystem as another protocol gets compromised

March 27, 2023
Litecoin holders praising LTC’s growth could be disappointed because…

Litecoin holders praising LTC’s growth could be disappointed because…

May 22, 2023

Popular Stories

  • New Python malware backdoors VMware ESXi servers for remote access

    Massive ESXiArgs ransomware attack targets VMware ESXi servers worldwide

    137 shares
    Share 55 Tweet 34
  • Facts and myths about the warriors who raided Europe and explored the New World

    137 shares
    Share 55 Tweet 34
  • Exploit released for actively abused ProxyNotShell Exchange bug

    137 shares
    Share 55 Tweet 34
  • New Windows Server updates cause domain controller freezes, restarts

    136 shares
    Share 54 Tweet 34
  • Bing Chat’s secret modes turn it into a personal assistant or friend

    136 shares
    Share 54 Tweet 34
Whats Current In

We bring you the best Premium WordPress Themes that perfect for news, magazine, personal blog, etc. Visit our landing page to see all features & demos.

LEARN MORE »

Recent Posts

  • How Blur achieved a new milestone from an unexpected source
  • Why Bitcoin will not retest $20,000 anytime soon
  • TRON bulls could push for another 5% hike given…

Categories

  • Apple Computer
  • Blockchain
  • Cyber Security
  • Tech News
  • Venture Capital

© 2023 JNews - Premium WordPress news & magazine theme by Jegtheme.

No Result
View All Result
  • Blockchain
  • Cyber Security
  • Gadgets & Hardware
  • Startups
    • Angel investing
    • Venture Capital
  • More Tech News
    • AI
    • App Development
    • Cloud & SaaS
    • Gaming
    • Web Development

© 2023 JNews - Premium WordPress news & magazine theme by Jegtheme.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
Are you sure want to unlock this post?
Unlock left : 0
Are you sure want to cancel subscription?