Skip to main content

VMware Releases Security Updates for Multiple Products

Report a cyber attack: call 0300 303 5222 or email [email protected]

Affected platforms

The following platforms are known to be affected:

VMware Carbon Black App Control (AppC) Versions: 8.6.x prior to 8.6.2, 8.5.x prior to 8.5.8, and 8.1.x and earlier

VMware Tools for Windows Versions: 11.x prior to 11.2.6

VMware Remote Console (VMRC) for Windows Versions: 12.x prior to 12.0.1

VMware App Volumes Versions: 4 prior to 4 R2103, and 2.x prior to 2.18.10


Threat details

Introduction

VMware has released two security advisories for vulnerabilities found in VMware products. A remote attacker could exploit some of these vulnerabilities to take control of an affected system.

The first advisory, VMSA-2021-0012, is marked as critical and addresses an authentication bypass vulnerability (CVE-2021-21998) in VMware Carbon Black App Control. The second advisory, VMSA-2021-0013, is marked as important and concerns a privilege escalation vulnerability (CVE-2021-21999) in VMware Tools for Windows, VMRC for Windows, and VMware App Volumes.


Remediation advice

Affected organisations are encouraged to review VMware security advisories VMSA-2021-0012 and VMSA-2021-0013 and apply any relevant updates.


Last edited: 24 June 2021 2:37 pm