CERT-In Vulnerability Note
CIVN-2023-0043
Multiple vulnerabilities in VMware products
Original Issue Date:February 10, 2023
Severity Rating: HIGH
Software Affected
- VMware Workstation version 17.x
- VMware vRealize Operations (vROps) version 8.6.x
Overview
Multiple vulnerabilities have been reported in VMware products which could be exploited by a remote attacker to bypass implemented security restrictions on the targeted system.
Description
1. Arbitrary file deletion vulnerability
(
CVE-2023-20854
)
This vulnerability exists in VMware Workstation due to improper access restrictions. An attacker could exploit this vulnerability by sending a specially-crafted request to the affected application. Successful exploitation of this vulnerability could allow an attacker to bypass implemented security restrictions and delete arbitrary files on the target system.
2. Cross Site Request Forgery (CSRF) Vulnerability
(
CVE-2023-20856
)
This vulnerability exists in VMware vRealize Operations (vROps) due to insufficient validation of the HTTP request origin. A remote attacker could exploit this vulnerability by tricking the victim to visit a specially crafted web page and perform arbitrary actions on behalf of the victim on the vulnerable website. Successful exploitation of this vulnerability could allow a remote attacker to bypass implemented security restrictions on the target system.
Solution
Apply appropriate updates as mentioned by vendor:
https://www.vmware.com/security/advisories/VMSA-2023-0002.html
https://www.vmware.com/security/advisories/VMSA-2023-0003.html
Vendor Information
VMware
https://www.vmware.com/security/advisories/VMSA-2023-0002.html
https://www.vmware.com/security/advisories/VMSA-2023-0003.html
References
VMware
https://www.vmware.com/security/advisories/VMSA-2023-0002.html
https://www.vmware.com/security/advisories/VMSA-2023-0003.html
CVE Name
CVE-2023-20854
CVE-2023-20856
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|