Category: Security Advisory

Workaround instructions to address CVE-2021-44228 and CVE-2021-45046 in vRealize Operations 8.x

Aria Security Advisory

This is most up-to-date document on how to remediate CVE-2021-44228 and CVE-2021-45046. On 15th of December 2021 VMware added workaround steps related to CVE-2021-45046. I will show you how to apply workaround. Please remember this is temporary solution as we are waiting for patch from VMware. RUN LIST: Log into the vRealize Operations Manager Admin…

Read more

VMware is going to update log4j to version 2.16

Security Advisory

Today VMware published update on log4j solution. As per statment on the vendor KB website says that VMware expect to fully address both CVE-2021-44228 and CVE-2021-45046 by updating log4j to version 2.16 in forthcoming releases of vCenter Server, as outlined by our software support policies. VMSA-2021-0028 will be updated when these releases are available. In…

Read more

-Dlog4j2.formatMsgNoLookups=true” or “class JndiLookup” is not valid workaround anymore!

Security Advisory

It looks like to workaround published by VMware is not valid anymore! On December 9, 2021 VMware released VMSA-2021-0028 to track the impact of an Apache Software Foundation security advisory for their extremely popular Log4j Java logging component on VMware products and services. An updated workaround for CVE-2021-44228, as well as guidance on a second vulnerability,…

Read more

This is a CRITICAL Advisory with the highest possible severity (CVSSv3 score of 10 out of 10) VMSA-2021-0028

Security Advisory

VMware published security advisory, VMSA-2021-0028, which impacts many VMware products through a Remote Code Execution (RCE) vulnerability via Apache Log4j.  This is a CRITICAL Advisory with the highest possible severity (CVSSv3 score of 10 out of 10).  The VMSA will be the source of truth for all developments around this issue: https://www.vmware.com/security/advisories/VMSA-2021-0028.html.  Evaluation is still underway, but a list of known affected products…

Read more

Security Advisory VMSA-2021-0020

Security Advisory

I wanted to make sure that you were aware of the CRITICAL  vCenter Server Security Advisory that was just released yesterday (21/09/2021).    Security Advisory VMSA-2021-0020  VMware vCenter Server updates address several CVE’s across all 3 supported versions of vCenter Server (6.5/6.7/7.0) with a maximum CVSSv3 base score of 9.8. Known Attack Vectors A malicious actor with network access to port 443 on vCenter…

Read more

Security Advisory VMSA-2021-0018

Security Advisory

Yesterday VMware released  IMPORTANT Security Advisory for vRealize Operations Manager, Please see below information on VMSA-2021-0018, Important Notes, and Security Patch PAK to address this Security Advisory: Security Advisory VMSA-2021-0018 – VMware vRealize Operations update addresses multiple security vulnerabilities (CVE-2021-22022,  CVE-2021-22023, CVE-2021-22024, CVE-2021-22025, CVE-2021-22026, CVE-2021-22027) with a maximum CVSSv3 base score of 8.6. Known Attack Vectors An unauthenticated malicious actor with network access to the vRealize Operations Manager API can perform a Server…

Read more

Security Advisory VMSA-2021-0014 (CVE-2021-21994, CVE-2021-21995)

Security Advisory

IMPORTANT Security Advisory that was released earlier yesterday (13-07-2021) Security Advisory VMSA-2021-0014 VMware ESXi updates address authentication and denial of service vulnerabilities (CVE-2021-21994, CVE-2021-21995) with a maximum CVSSv3 base score of 7.0. Known Attack Vectors A malicious actor with network access to port 5989 on ESXi may exploit this issue to bypass SFCB authentication by sending a specially crafted request. NOTE: SFCB is disabled…

Read more

PrintNightmare – CVE-2021-1675 & CVE-2021-34527

Security Advisory

There is no patch as of yet, hence this workaround need to be applied. PowerShell: Determine if the Print Spooler service is running: Stop and disable the Print Spooler service Impact of workaround Disabling the Print Spooler service disables the ability to print both locally and remotely. BigFix: Run this action: waithidden powershell.exe Stop-Service -Name spooler…

Read more

Security Advisory VMSA-2021-0010

Security Advisory

This critical alert is to inform you of two new vulnerabilities identified in VMware vSphere 6.5, 6.7 and 7.0. The vulnerabilities include VMware Cloud Foundation 3.x/4.x environments. This is covered by VMSA-2021-0010. Further information is available in a Blog post and FAQ (Links below – Please visit these sites) VMware engineering identified multiple security vulnerabilities that affect vCenter…

Read more