Skip to main content

VMware Releases Security Update

VMware security update addresses four vulnerabilities in VMware Aria Operations and Cloud Foundation

Report a cyber attack: call 0300 303 5222 or email [email protected]

Summary

VMware security update addresses four vulnerabilities in VMware Aria Operations and Cloud Foundation


Threat details

Introduction

VMware has released a security update to address four vulnerabilities in VMware Aria Operations and Cloud Foundation. These vulnerabilities include:

CVE-2023-20877 with a CVSSv3 score of 8.8, relates to a privilege escalation vulnerability. An authenticated attacker with Read-Only privileges could perform code execution leading to privilege escalation. 

CVE-2023-20878 with a CVSSv3 score of 6.6, relates to a deserialisation vulnerability. An attacker with administrative privileges could execute arbitrary commands and disrupt the system. 

CVE-2023-20879 with a CVSSv3 score of 6.7, relates to a Local Privilege Escalation. An attacker with administrative privileges in the Aria Operations application could gain root access to the underlying operating system. 

CVE-2023-20880 with a CVSSv3 score of 6.4, relates to a Local Privilege Escalation. An attacker with administrative access to the local system could escalate privileges to root.


Remediation advice

Affected organisations are encouraged to review the VMware Security Advisory VMSA-2023-0009 and apply any relevant updates.



Last edited: 15 May 2023 3:05 pm