1 min read

Update VMWare Apps Now for Critical Security Vulnerabilities

The Cybersecurity and Infrastructure Security Agency (CISA) has issued an advisory that serves as a stark warning.

If you’re using VMware products that are impacted by recently disclosed critical security flaws, either patch them immediately or remove them from your network.

CISA issued the dire warning because the last time critical security flaws were discovered in VMware products, hackers began exploiting them within 48 hours after they were disclosed.

In this case, the two recently disclosed issues are being tracked as CVE-2022-22972 and CVE-2022-22973, with severity scores of 9.8 and 10, respectively.

The flaws impact the following:

  • VMware Workspace ONE Access (Access)
  • VMware Identity Manager (vIDM)
  • VMware vRealize Automation (vRA)
  • VMware Cloud Foundation
  • and vRealize Suite Lifecycle Manager

Patches that protect against exploitation of these flaws are already available and VMware is likewise advising customers using the impacted products to apply them as soon as possible, describing the ramifications of delaying as “serious.”

This isn’t the first time VMware’s products have been in the spotlight.  Just last month, there were two other flaws (tracked as CVE-2022-22954 and CVE-2022-22960), which impacted the same products.

Although VMware moved quickly in that instance, releasing a patch very quickly, hackers were able to reverse engineer those patches and exploit the flaws anyway.

Worst of all, the security firm Rapid7 has already seen evidence of the exploitation of these flaws in the wild. So every day you don’t patch, you’ve essentially got a target on your back.

CISA has issued the same warning to federal agencies, saying:

“CISA expects threat actors to quickly develop a capability to exploit these newly released vulnerabilities in the same impacted VMware products. Exploiting the above vulnerabilities permits attackers to trigger a server-side template injection that may result in remote code execution (CVE-2022-22954); escalate privileges to ‘root’ (CVE-2022-22960 and CVE-2022-22973); and obtain administrative access without the need to authenticate (CVE-2022-22972).”

Serious issues indeed.  Update as soon as possible.

Used with permission from Article Aggregator

Your Law Firm's IT Infrastructure Is Either Ready for Advanced Legal Software…or It Isn't

Your Law Firm's IT Infrastructure Is Either Ready for Advanced Legal Software…or It Isn't

Most law firms don’t discover their IT infrastructure is inadequate until they’re already halfway through deploying a new legal platform and things...

Read the full blog
Your Legal Case Called. Your Tech Stack Needs Work.

Your Legal Case Called. Your Tech Stack Needs Work.

Managing complex litigation without the right tools is like trying to win a trial with a yellow legal pad and a prayer. It can be done...but why...

Read the full blog
Alert Channels That Actually Work When It Counts

Alert Channels That Actually Work When It Counts

An emergency alert is only useful if people actually receive it, notice it, and understand what to do next.

Read the full blog

1 min read

Fortinet VPN User Passwords May Have Been Leaked Online

Hackers recently released a list of nearly half a million Fortinet VPN usernames and passwords onto the Dark Web. The group behind the attack claims...

Read the full blog
Secure Portals: The Modern Digital Vault Every Law Firm Requires

1 min read

Secure Portals: The Modern Digital Vault Every Law Firm Requires

Picture this: your client sends you their tax returns, medical records, and confidential business documents via email. They hit send, the files...

Read the full blog

1 min read

Law Firm IT vs. Cyber Threats and Data Vulnerabilities

Law firms are constantly facing a critical clash between their IT infrastructure and the ever-evolving threats posed by cyber-attacks and data...

Read the full blog