VMware Releases Security Updates for Carbon Black App Control
Security update to address two critical vulnerabilities in Carbon Black App Control
Summary
Security update to address two critical vulnerabilities in Carbon Black App Control
Affected platforms
The following platforms are known to be affected:
Threat details
Introduction
VMware has released a security update to address two vulnerabilities in Carbon Black App Control. Both vulnerabilities are critical severity, with each having a CVSSv3 rating of 9.1.
CVE-2022-22951 is an OS command injection vulnerability due to improper input validation. This vulnerability could allow an authenticated attacker, with high privileges and network access to VMware App Control administration interface, to execute commands on the server leading to remote code execution (RCE).
CVE-2022-22952 is a file upload vulnerability in App Control Server. This vulnerability could allow an attacker, with administration access to VMware App Control administration interface, to execute code on the Windows instance with App Control Server installed by uploading a specially crafted file.
Remediation advice
Affected organisations are encouraged to review VMware Security Advisory VMSA-2022-0008 and apply any relevant updates.
Definitive source of threat updates
CVE Vulnerabilities
Last edited: 24 March 2022 11:52 am