Threat Advisory

VMware fixes critical Cloud Foundation remote code execution bug

Threat: Vulnerability
Criticality: High
[subscribe_to_unlock_form]

A security patch has been released for a flaw that was found in Xstream, a simple library to serialize objects to XML and back again. CVE-2021-39144 is a Remote Command Execution vulnerability with a CVSSv3 score of 9.8/10 which if exploited a malicious actor can get remote code execution in the context of 'root' on the appliance. This flaw allows a remote attacker to load and execute arbitrary code from a remote host by manipulating the processed input stream.

Recommendation:[/subscribe_to_unlock_form]

A security patch has been released for a flaw that was found in Xstream, a simple library to serialize objects to XML and back again. CVE-2021-39144 is a Remote Command Execution vulnerability with a CVSSv3 score of 9.8/10 which if exploited a malicious actor can get remote code execution in the context of 'root' on the appliance. This flaw allows a remote attacker to load and execute arbitrary code from a remote host by manipulating the processed input stream.

Recommendation:[emaillocker id="1283"]

We strongly recommend you to update to the latest version (6.4.14) to patch the vulnerability.

References:

The following reports contain further technical details:

https://www.vmware.com/security/advisories/VMSA-2022-0027.html

[/emaillocker]
crossmenu