Skip to main content

VMware Releases Security Updates for Carbon Black App Control

Security update to address two critical vulnerabilities in Carbon Black App Control

Report a cyber attack: call 0300 303 5222 or email [email protected]

Summary

Security update to address two critical vulnerabilities in Carbon Black App Control


Threat details

Introduction

VMware has released a security update to address two vulnerabilities in Carbon Black App Control. Both vulnerabilities are critical severity, with each having a CVSSv3 rating of 9.1. 

CVE-2022-22951 is an OS command injection vulnerability due to improper input validation. This vulnerability could allow an authenticated attacker, with high privileges and network access to VMware App Control administration interface, to execute commands on the server leading to remote code execution (RCE).

CVE-2022-22952 is a file upload vulnerability in App Control Server. This vulnerability could allow an attacker, with administration access to VMware App Control administration interface, to execute code on the Windows instance with App Control Server installed by uploading a specially crafted file.


Remediation advice

Affected organisations are encouraged to review VMware Security Advisory VMSA-2022-0008 and apply any relevant updates.



Last edited: 24 March 2022 11:52 am