Category: Security Advisory

Critical Severity – VMSA-2022-0010 – VMware Tanzu

Security Advisory

VMware published security advisory VMSA-2022-0010. A critical vulnerability in the Spring Framework project identified by CVE-2022-22965 has been publicly disclosed which impacts VMware products: VMware Tanzu Application Service for VMs VMware Tanzu Operations Manager VMware Tanzu Kubernetes Grid Integrated Edition (TKGI) Multiple products impacted by remote code execution vulnerability (CVE-2022-22965), a malicious actor with network access to…

Read more

VMware vCenter Server 7.0 Update 3d has been released!

Security Advisory vCenter

VMware released a new update for vCenter Server 7.0. vCenter Server 7.0 Update 3d ISO Build 19480866. This release resolves CVE-2022-22948 View VMware vCenter Release and Build Number History NOTE: If your source system contains the ESXi 7.0 Update 2 release (build number 17630552) or later builds with Intel drivers, before upgrading to vCenter Server 7.0 Update 3d,…

Read more

ESXi 7.0 Update 3d has been released

ESXi Security Advisory

Yesterday VMware released a new update ESXi 7.0 Update 3d ISO Build 19482537. The update has severity CRITICAL! Download Filename: VMware-ESXi-7.0U3d-19482537-depot.zip Build: 19482537 Download Size: 586.8 MB md5sum: 22fca2ef1dc38f490d1635926a86eb02 sha256checksum: 2ef5b43b4e9d64a9f48c7ea0ee8561f7619c9ab54e874974b7f0165607a2355a Host Reboot Required: Yes Virtual Machine Migration or Shutdown Required: Yes NOTE: If your source system contains the ESXi 7.0 Update 2 release (build number 17630552) or later…

Read more

How to determine if my virtual machines have a USB controller attached and how to remove it?

PowerShell Security Advisory

In the wake of recent published VMSA-2022-0004 admins can wonder how to determine if Virtual Machine has a USB controller attached. Now thanks to PowerCLI it is an easy task. NOTE: I did not come up with this code, this code was originally published on VMware advisory website Before admins can remove USB controllers, The virtual…

Read more

Critical Severity – VMSA-2022-0004 – VMware ESXi, Workstation, and Fusion

Security Advisory

Multiple vulnerabilities in VMware ESXi, Workstation, and Fusion were privately reported to VMware. Updates are available to remediate these vulnerabilities in affected VMware products. These issues were discovered as part of the Tianfu Cup, a Chinese security event that VMware participates in. These vulnerabilities were reported to the Chinese government by the researchers that discovered them,…

Read more

vCenter Server 7.0 Update 3c has been released.

Security Advisory vCenter

Finally, VMware released a new update for vCenter Server addressing all the issues documented in KB86281, also including Apache log4j version 2.17. IMPORTANT: VMware removed ESXi 7.0 Update 3, 7.0 Update 3a, and 7.0 Update 3b from all sites on November 19, 2021 due to an upgrade-impacting issue. Build 19193900 for ESXi 7.0 Update 3c ISO replaces build 18644231, 18825058, and 18905247 for ESXi…

Read more

Is VMware going to update log4j to version 2.17

Security Advisory

As we know by now that the only solution for Log4j is to get it updated to version 2.17. The question is if VMware is going to update log4j to version 2.17? Here is an official answer from VMware: VMware regularly updates open-source components inside our products as new versions ship. As we’ve noted in…

Read more

Workaround Instructions For CVE-2021-22045 on VMware ESXi Hosts (87249)

Security Advisory

VMware just released new security advisory for ESXi hosts. For ESXi 6.5 and 6.7 there are patches ready, but for 7.0 there is only workaround. ESXi Version Fixed Version Build Number Release date 6.5 6.5 P07 18678235 October 12th 2021 6.7 6.7 P06 18828794 November 23rd 2021 7.0 Pending Pending Pending As the workaround all…

Read more

Update on VMSA-2021-0028

Security Advisory

NSX-T Data Center (2.5.0-3.1.3) (KB87086) – https://kb.vmware.com/s/article/87086?lang=en_US •December 17th 2021 – 15:00 PST [6:00PM EST]: Added detail regarding NSX T 3.2.0 release pertinent to CVE-2021-44228 & CVE-2021-45046. •December 17th 2021 – 17:00 PST [8:00PM EST: Changed the workaround provided to the new VMware recommended NSX-T workaround. •December 20th 2021 – 4.00 PM IST [5:30AM EST]: Added a note…

Read more