{"id":16663,"date":"2023-01-24T22:32:55","date_gmt":"2023-01-24T21:32:55","guid":{"rendered":"https:\/\/www.show.it\/vmware-plugs-critical-code-execution-flaws\/"},"modified":"2023-01-24T22:32:55","modified_gmt":"2023-01-24T21:32:55","slug":"vmware-plugs-critical-code-execution-flaws","status":"publish","type":"post","link":"https:\/\/www.show.it\/en\/vmware-plugs-critical-code-execution-flaws\/","title":{"rendered":"VMware Plugs Critical Code Execution Flaws"},"content":{"rendered":"<p><strong>Virtualization technology giant VMware on Tuesday shipped its first security bulletin for 2023 with patches for multiple critical-level flaws that expose businesses to remote code execution attacks.<\/strong><\/p>\n<p>VMware said the security defects affect users of its VMware vRealize Log Insight and could be exploited by an unauthenticated attacker to take full control of a target system.<\/p>\n<p>VMware\u2019s VRealize Log Insight is a log collection and analytics virtual appliance used by administrators to collect, view, manage and analyze syslog data.<\/p>\n<p>The company said the most serious of the four documented flaws carry a CVSS severity score of 9.8 out of 10, adding to the urgency for organizations to apply available patches.<\/p>\n<p>An <a href=\"https:\/\/www.vmware.com\/security\/advisories\/VMSA-2023-0001.html\">advisory<\/a> from the Palo Alto, Calif. company described the flaws \u2014 CVE-2022-31706, CVE-2022-31704, CVE-2022-31710 and CVE-2022-31711 \u2013as directory traversal and broken access control issues with dangerous implications.\u00a0<\/p>\n<p>\u201cAn unauthenticated, malicious actor can inject files into the operating system of an impacted appliance which can result in remote code execution,\u201d VMware warned.<\/p>\n<p>The company also shipped fixes for a separate deserialization vulnerability that exposes vRealize Log Insight users to denial-of-service attacks.\u00a0\u00a0<\/p>\n<p>VMware also patched an information disclosure issue that allowed attackers to remotely collect sensitive session and application information without authentication.\u00a0\u00a0\u00a0<\/p>\n<p><strong>Related: <\/strong><a href=\"https:\/\/www.securityweek.com\/vmware-patches-vm-escape-flaw-exploited-geekpwn-event\/\">VMware Patches VM Escape Flaw Exploited at Geekpwn Event<\/a><\/p>\n<p><strong>Related: <\/strong><a href=\"https:\/\/www.securityweek.com\/gaping-authentication-bypass-holes-vmware-workspace-one\/\">Gaping Authentication Bypass Holes in VMware Workspace One<\/a><\/p>\n<p><strong>Related: <\/strong><a href=\"https:\/\/www.securityweek.com\/vmware-confirms-workspace-one-exploits-wild\/\">VMware Confirms Workspace One Exploits in the Wild<\/a><\/p>\n<p>The post <a rel=\"nofollow\" href=\"https:\/\/www.securityweek.com\/vmware-plugs-critical-code-execution-flaws\/\">VMware Plugs Critical Code Execution Flaws<\/a> appeared first on <a rel=\"nofollow\" href=\"https:\/\/www.securityweek.com\/\">SecurityWeek<\/a>.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Virtualization technology giant VMware on Tuesday shipped its first security bulletin for 2023 with patches for multiple critical-level flaws that expose businesses to remote code execution attacks. VMware said the security defects affect users of its VMware vRealize Log Insight and could be exploited by an unauthenticated attacker to take full control of a target [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":16664,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[89,90,23],"tags":[],"class_list":["post-16663","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-remote-code-execution","category-vmware","category-vulnerabilities"],"acf":[],"_links":{"self":[{"href":"https:\/\/www.show.it\/en\/wp-json\/wp\/v2\/posts\/16663","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.show.it\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.show.it\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.show.it\/en\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.show.it\/en\/wp-json\/wp\/v2\/comments?post=16663"}],"version-history":[{"count":0,"href":"https:\/\/www.show.it\/en\/wp-json\/wp\/v2\/posts\/16663\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.show.it\/en\/wp-json\/wp\/v2\/media\/16664"}],"wp:attachment":[{"href":"https:\/\/www.show.it\/en\/wp-json\/wp\/v2\/media?parent=16663"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.show.it\/en\/wp-json\/wp\/v2\/categories?post=16663"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.show.it\/en\/wp-json\/wp\/v2\/tags?post=16663"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}