Skip to main content

VMware Releases Security Updates

Security updates address one Critical vulnerability in VMware Carbon Black App Control and one vulnerability in VMware vRealize Orchestrator rated as Important

Report a cyber attack: call 0300 303 5222 or email [email protected]

Summary

Security updates address one Critical vulnerability in VMware Carbon Black App Control and one vulnerability in VMware vRealize Orchestrator rated as Important


Threat details

Introduction

VMware has released security updates to address a Critical vulnerability in Carbon Black App Control and a vulnerability in vRealize Orchestrator rated as Important. CVE-2023-20858 is a critical injection vulnerability in Carbon Black App Control with a CVSSv3 rating of 9.1. A remote attacker with privileged access could exploit this vulnerability to gain access to the underlying operating system.

CVE-2023-20855 is a XML External Entity (XXE) vulnerability in vRealize Orchestrator with a CVSSv3 rating of 8.8. A remote attacker with non-administrative access could exploit this vulnerability to bypass XML parsing restrictions, which could lead to access of sensitive information or privilege escalation.


Remediation advice

Affected organisations are encouraged to review the VMware Security Advisories page and apply any relevant updates.


Remediation steps

Type Step
Patch

VMware Carbon Black App Control updates address an injection vulnerability | VMSA-2023-0004


https://www.vmware.com/security/advisories/VMSA-2023-0004.html
Patch

VMware vRealize Orchestrator update addresses an XML External Entity (XXE) vulnerability | VMSA-2023-0005


https://www.vmware.com/security/advisories/VMSA-2023-0005.html

Last edited: 22 February 2023 3:11 pm