VMware Releases Security Update
VMware security update addresses four vulnerabilities in VMware Aria Operations and Cloud Foundation
Summary
VMware security update addresses four vulnerabilities in VMware Aria Operations and Cloud Foundation
Affected platforms
The following platforms are known to be affected:
Threat details
Introduction
VMware has released a security update to address four vulnerabilities in VMware Aria Operations and Cloud Foundation. These vulnerabilities include:
CVE-2023-20877 with a CVSSv3 score of 8.8, relates to a privilege escalation vulnerability. An authenticated attacker with Read-Only privileges could perform code execution leading to privilege escalation.
CVE-2023-20878 with a CVSSv3 score of 6.6, relates to a deserialisation vulnerability. An attacker with administrative privileges could execute arbitrary commands and disrupt the system.
CVE-2023-20879 with a CVSSv3 score of 6.7, relates to a Local Privilege Escalation. An attacker with administrative privileges in the Aria Operations application could gain root access to the underlying operating system.
CVE-2023-20880 with a CVSSv3 score of 6.4, relates to a Local Privilege Escalation. An attacker with administrative access to the local system could escalate privileges to root.
Remediation advice
Affected organisations are encouraged to review the VMware Security Advisory VMSA-2023-0009 and apply any relevant updates.
Definitive source of threat updates
CVE Vulnerabilities
Last edited: 15 May 2023 3:05 pm