VMware Releases Security Updates for Multiple Products
Affected platforms
The following platforms are known to be affected:
VMware Carbon Black App Control (AppC) Versions: 8.6.x prior to 8.6.2, 8.5.x prior to 8.5.8, and 8.1.x and earlier
VMware Tools for Windows Versions: 11.x prior to 11.2.6
VMware Remote Console (VMRC) for Windows Versions: 12.x prior to 12.0.1
VMware App Volumes Versions: 4 prior to 4 R2103, and 2.x prior to 2.18.10
Threat details
Introduction
VMware has released two security advisories for vulnerabilities found in VMware products. A remote attacker could exploit some of these vulnerabilities to take control of an affected system.
The first advisory, VMSA-2021-0012, is marked as critical and addresses an authentication bypass vulnerability (CVE-2021-21998) in VMware Carbon Black App Control. The second advisory, VMSA-2021-0013, is marked as important and concerns a privilege escalation vulnerability (CVE-2021-21999) in VMware Tools for Windows, VMRC for Windows, and VMware App Volumes.
Remediation advice
Affected organisations are encouraged to review VMware security advisories VMSA-2021-0012 and VMSA-2021-0013 and apply any relevant updates.
CVE Vulnerabilities
Last edited: 24 June 2021 2:37 pm