iTnews Asia
  • Home
  • News
  • Security

VMware Carbon Black has critical vulnerability

VMware Carbon Black has critical vulnerability

Patch also issued for vRealize, VCF bug.

By Richard Chirgwin on Feb 22, 2023 11:09AM

VMware has disclosed a critical vulnerability in its Carbon Black endpoint security platform.

Carbon Black provides application control, anti-virus and policy enforcement for enterprise endpoints under a single admin console.

Carbon Black’s application control versions 8.7x, 8.8x and 8.9x running on Windows are subject to CVE-2023-20858, which carries a critical CVSS score of 9.1.

VMware describes it as an injection vulnerability. An attacker would need compromised user credentials to exploit the bug, since they need privileged access to the app control administration console via the network.

With access, an attacker can then feed the console crafted input, and get access to the underlying server operating system.

The bug was discovered by HackerOne researcher Jari Jääskelä.

The company also announced CVE-2023-20855, a CVSS 8.8-scored vulnerability in its vRealize Orchestrator, vRealize Automation, and VMware Cloud Foundation products.

“A malicious actor, with non-administrative access to vRealize Orchestrator, may be able to use specially crafted input to bypass XML parsing restrictions leading to access to sensitive information or possible escalation of privileges”, VMware’s advisory stated.

The bug was reported by Germany’s State Office for Information Technology and Statistics (IT.NRW).

To reach the editorial team on your feedback, story ideas and pitches, contact them here.
Copyright © iTnews.com.au . All rights reserved.
Tags:
carbon black security vmware

Related Articles

  • Beware the rise of ‘vishing’ as a cyber threat in APAC
  • Proofpoint CEO: A tool-based approach for cybersecurity is impractical
  • Akamai: AI-security is both a security imperative and an economic necessity
  • The real-life Tom & Jerry chase
Share on Twitter Share on Facebook Share on LinkedIn Share on Whatsapp Email A Friend

Most Read Articles

Beware the rise of ‘vishing’ as a cyber threat in APAC

Beware the rise of ‘vishing’ as a cyber threat in APAC

Proofpoint CEO: A tool-based approach for cybersecurity is impractical

Proofpoint CEO: A tool-based approach for cybersecurity is impractical

Akamai: AI-security is both a security imperative and an economic necessity

Akamai: AI-security is both a security imperative and an economic necessity

The real-life Tom & Jerry chase

The real-life Tom & Jerry chase

All rights reserved. This material may not be published, broadcast, rewritten or redistributed in any form without prior authorisation.
Your use of this website constitutes acceptance of Lighthouse Independent Media's Privacy Policy and Terms & Conditions.