News: 1674614712

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Logfile management is no fun. Now it's a nightmare thanks to critical-rated VMware flaws

(2023/01/25)


VMware has issued fixes for four vulnerabilities, including two critical 9.8-rated remote code execution bugs, in its vRealize Log Insight software.

There are no reports (yet) of nation-state thugs or cybercriminals finding and exploiting these bugs, according to VMware. However, it's a good idea to patch sooner than later to avoid being patient zero.

vRealize Log Insight is a log management tool - everyone's favourite tas, not - and while it may not be as popular as some of the virtualization giant's other products, VMware's ubiquity across enterprises and governments and practice of bundling products means holes in its products are always very attractive targets for miscreants looking to make a buck and/or steal sensitive information.

[1]

Case in point: the state-sponsored Iranian crew that, in November, exploited the high-profile Log4j vulnerability to [2]infiltrate an unpatched VMware Horizon server within the US federal government and deployed the XMRig crypto miner.

[3]

[4]

The two most serious bugs in today's security advisory include a directory traversal vulnerability (CVE-2022-31703) and a broken access control vulnerability (CVE-2022-31704). Both received a near-perfect 9.8 out of 10 CVSS rating.

While the two flaws provide different paths for a miscreant to gain unauthorized access to restricted resources, the result of a successful exploit is the same.

[5]

"An unauthenticated, malicious actor can inject files into the operating system of an impacted appliance which can result in remote code execution," VMware [6]warned about both critical bugs.

The third bug, CVE-2022-31710, is a deserialization vulnerability in vRealize Log Insight that could allow an unauthenticated, remote attacker to manipulate data and cause a denial of service attack. It's in the important severity range, with a 7.5 CVSS score.

And finally, CVE-2022-31711 is an information disclosure bug that could allow an unauthenticated attacker to remotely steal sensitive session and application information. It received a 5.3 severity rating.

[7]

Updating to VMware vRealize Log Insight 8.10.2 should plug all four holes, according to the vendor, and VMware issued [8]workaround instructions as well.

[9]VMware warns of three critical holes in remote-control tool

[10]Miscreants sure do love ransacking cloud networks, more so than before

[11]Apple emits emergency patch for older iPhones after snoops pounce on WebKit hole

[12]Who is exploiting VMware right now? Probably Iran's Rocket Kitten, to name one

The Zero Day Initiative found all four bugs and reported them to VMware.

"We're not aware of any public exploit code or active attacks using this vulnerability," Dustin Childs, head of threat awareness at Trend Micro's ZDI, told The Register . "While we have no current plans to publish proof of concept for this bug, our research in VMware and other virtualization technologies continues."

The latest security holes come a couple of months after VMware disclosed [13]three critical-rated flaws in Workspace ONE Assist for Windows – a product used by IT and help desk staff to remotely take over and manage employees' devices.

Those flaws were rated 9.8 out of 10 on the CVSS scale.

A miscreant able to reach a Workspace ONE Assist deployment, either over the internet or on the network, can exploit any of these three bugs to obtain administrative access without the need to authenticate. Then, the intruder or rogue insider can contact users to offer them assistance that is anything but helpful, such as seizing control of devices. ®

Get our [14]Tech Resources



[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/patches&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2Y9C3cVzJDC0LPx@bCYBzNQAAAME&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[2] https://www.theregister.com/2022/11/16/iranian_cyberspies_log4j/

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/patches&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Y9C3cVzJDC0LPx@bCYBzNQAAAME&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/patches&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Y9C3cVzJDC0LPx@bCYBzNQAAAME&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/patches&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Y9C3cVzJDC0LPx@bCYBzNQAAAME&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[6] https://www.vmware.com/security/advisories/VMSA-2023-0001.html

[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/patches&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Y9C3cVzJDC0LPx@bCYBzNQAAAME&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[8] https://kb.vmware.com/s/article/90635

[9] https://www.theregister.com/2022/11/09/vmware_workspace_one_assist_critical_flaws/

[10] https://www.theregister.com/2023/01/20/cloud_networks_under_attack/

[11] https://www.theregister.com/2023/01/24/apple_iphone_bug_under_exploit/

[12] https://www.theregister.com/2022/04/26/iran_rocket_kitten_vmware_exploit/

[13] https://www.theregister.com/2022/11/09/vmware_workspace_one_assist_critical_flaws/

[14] https://whitepapers.theregister.com/



Ever Onward! Ever Onward!
That's the sprit that has brought us fame.
We're big but bigger we will be,
We can't fail for all can see, that to serve humanity
Has been our aim.
Our products now are known in every zone.
Our reputation sparkles like a gem.
We've fought our way thru
And new fields we're sure to conquer, too
For the Ever Onward IBM!
-- Ever Onward, from the 1940 IBM Songbook