Categories: Vulnerability

VMware Issues Patches for Critical Flaws in OS Command Injection Vulnerability

A critical OS Command injection and File upload vulnerabilities were affecting the VMware Carbon Black App Control (AppC). VMware has fixed the issues and has released patches for the same. The details of the vulnerability are as follows:

Advisory ID:

VMSA-2022-0008

CVSSv3 Range:

9.1

Issue Date:

2022-03-23

Updated On:

2022-03-23 (Initial Advisory)

CVE(s):

CVE-2022-22951, CVE-2022-22952

Synopsis:

VMware Carbon Black App Control update addresses multiple vulnerabilities (CVE-2022-22951, CVE-2022-22952)

Products that are impacted

  • VMware Carbon Black App Control (AppC)

CVE-2022-22951 (OS command injection vulnerability in VMware Carbon Black App Control)

Summary

An OS command Injection was found in the VMware Carbon Black App Control which was given a maximum CVSSv3 base score of 9.1 by VMware. An attacker with high privilege authentication to the VMware App Control administration interface can execute commands on the server which was due to the improper validation of input leading to remote code execution.

Remediation

For remediating this issue, VMware has released patches along with Response Matrix and Fixed version details.

Thanks to the Reporter

VMware also thanked Jari Jääskelä for reporting this issue.

CVE-2022-22952 (File Upload Vulnerability VMware Carbon Black App Control)

Summary

A file upload vulnerability was found in the VMware Carbon Black App Control which was given a maximum CVSSv3 base score of 9.1 by VMware. An attacker with high privilege authentication to the VMware App Control administration interface can execute commands on the Windows instance in which the AppC server is hosted by uploading a specially crafted file.

Remediation

For remediating this issue, VMware has released patches along with Response Matrix and Fixed version details.

Thanks to the Reporter

VMware also thanked Jari Jääskelä for reporting this issue.

Fixed Version

VMware Carbon Black App Control 8.8.2, 8.7.4, 8.6.6, 8.5.14 have these issues fixed and updated. VMware has provided release notes for these patches.

You can follow us on LinkedinTwitterFacebook for daily Cybersecurity and hacking news updates.

Guru Baran

Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.

Recent Posts

Google Chrome 153 Update Fixes 42 Security Flaws, Including 3 Critical Ones

Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…

31 minutes ago

CISA and NIST Release Technical Checklist for Safeguarding Identity Tokens From Theft and Misuse

The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology…

10 hours ago

CISA Shares 17 Techniques Used by Hackers to Compromise Active Directory Environments

CISA and five international cybersecurity agencies have released detailed guidance describing 17 common techniques hackers…

11 hours ago

Apple Rolls Out Massive Security Update Fixing 273 Vulnerabilities Across Its Devices

Apple has released one of its largest coordinated security rollouts, addressing 273 distinct critical vulnerabilities…

12 hours ago

How to Keep Malware’s Rotating Infrastructure From Becoming a Detection Gap

You can’t detect today's attacks with yesterday’s threat intelligence; that’s how you could briefly formulate…

12 hours ago

Microsoft Bans Its AI Models From Launching Cyberattacks or Escalating Their Own Access

Microsoft has published a draft Humanist AI Code of Conduct that would prohibit its in-house…

12 hours ago