Skip to main content

VMware Releases Updates and Workarounds for CVE-2020-4006

Report a cyber attack: call 0300 303 5222 or email [email protected]

Affected platforms

The following platforms are known to be affected:

VMware Access Versions: 20.01 and 20.10 (on Linux)

VMware Cloud Foundation Versions: all 4.x

VMware vIDM Versions: 3.3.1, 3.3.2, and 3.3.3 (on Linux)

VMware vIDM Connector Versions: 3.3.1, 3.3.2, 3.3.3, and 19.03

VMware vRealize Suite Lifecycle Manager Versions: all 8.x


Threat details

Introduction

VMware has released updates and workarounds to address a vulnerability in VMware Workspace One Access, Access Connector, Identity Manager, and Identity Manager Connector. An attacker could exploit this vulnerability to take control of an affected system.


Threat updates

Date Update
8 Dec 2020 CVE-2020-4006 under active exploitation

The US National Security Agency has published a report (via CISA) on Russian state-sponsored attackers actively exploiting CVE-2020-4006.

At the time of publication, it is unclear what the attackers goal is.


Remediation advice

Affected organisations are encouraged to review VMware security advisory VMSA-2020-0027.2 and apply any necessary updates or workarounds.



Last edited: 8 December 2020 11:31 am