web analytics

VMware fixed a critical flaw in vRealize that allows executing arbitrary code as root – Source: securityaffairs.com

Rate this post

Source: securityaffairs.com – Author: Pierluigi Paganini.

VMware fixed two severe flaws, tracked as CVE-2023-20864 and CVE-2023-20865, impacting the VMware Aria Operations for Logs product.

The virtualization giant VMware released security updates to address two critical vulnerabilities, tracked as CVE-2023-20864 and CVE-2023-20865, impacting the VMware Aria Operations for Logs product (formerly vRealize Log Insight).

The vulnerability CVE-2023-20864 (CVSSv3 base score of 9.8) is a deserialization issue that can be exploited by an unauthenticated attacker with network access to VMware Aria Operations for Logs to execute arbitrary code as root.

The second vulnerability, tracked as CVE-2023-20865 (CVSSv3 base score of 7.2), is a command injection issue that can be exploited by an attacker with administrative privileges in Aria Operations for Logs to execute arbitrary commands as root. The flaw was reported to the company by Y4er & MoonBack of 埃文科技.

Please vote for Security Affairs (https://securityaffairs.com/) as the best European Cybersecurity Blogger Awards 2022 – VOTE FOR YOUR WINNERS

Vote for me in the sections:

  • The Teacher – Most Educational Blog
  • The Entertainer – Most Entertaining Blog
  • The Tech Whizz – Best Technical Blog
  • Best Social Media Account to Follow (@securityaffairs)

Please nominate Security Affairs as your favorite blog.

Nominate here: https://docs.google.com/forms/d/e/1FAIpQLSfaFMkrMlrLhOBsRPKdv56Y4HgC88Bcji4V7OCxCm_OmyPoLw/viewform

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, vRealize)




Original Post URL: https://securityaffairs.com/145087/security/critical-flaw-vmware-vrealize.html

Category & Tags: Breaking News,Security,Hacking,hacking news,information security news,IT Information Security,Pierluigi Paganini,Security Affairs,Security News,VMware,VMware Aria Operations for Logs – Breaking News,Security,Hacking,hacking news,information security news,IT Information Security,Pierluigi Paganini,Security Affairs,Security News,VMware,VMware Aria Operations for Logs

Views: 0

LinkedIn
Twitter
Facebook
WhatsApp
Email

advisor pick´S post