Two actively exploited vulnerabilities affect multiple VMware products
For a detailed advisory, download the pdf file here
Multiple vulnerabilities have been discovered in VMware products. Two of these have been exploited in the wild.
The first zero-day vulnerability, CVE-2022-22954, is a server-side template injection flaw. An attacker could exploit this bug to gain network access and remotely execute code in order to deliver cryptominers.
Several Proof of Concepts (PoCs) of this issue indicates that it could be weaponized by ransomwares/ threat actor groups soon.
The second zero-day vulnerability, CVE-2022-22960 exists due to improper permissions in support scripts. An attacker could exploit this issue to escalate privileges to root on vulnerable servers.
Organizations have advised the patch of all these vulnerabilities as soon as possible to avoid exploitation.
Vulnerability Detail
Patch Links
https://kb.vmware.com/s/article/88099
References
https://www.vmware.com/security/advisories/VMSA-2022-0011.html
Potential MITRE ATT&CK TTPs are:
TA0042: Resource Development
TA0001: Initial Access
TA0004: Privilege Escalation
T1588: Obtain Capabilities
T1588.006: Obtain Capabilities: Vulnerabilities
T1190: Exploit Public-Facing Application
T1548: Abuse Elevation Control Mechanism
T1068: Exploitation for Privilege Escalation
What’s new on HivePro
Get through updates and upcoming events, and more directly in your inbox