<div class="separator"><a href="https://thehackernews.com/images/-j136_z7UZNc/YNQ7Y__WRWI/AAAAAAAAC-U/oIYaMgYSXVYLJkHR5taYmCdxvH79jX-ewCLcBGAsYHQ/s0/vmware.jpg"></a></div> <p>VMware has rolled out security updates to resolve a critical flaw affecting Carbon Black App Control that could be exploited to bypass authentication and take control of vulnerable systems.</p> <p>The vulnerability, identified as CVE-2021-21998, is rated 9.4 out of 10 in severity by the industry-standard Common Vulnerability Scoring System (CVSS) and affects App Control (AppC) versions 8.0.x, 8.1.x, 8.5.x, and 8.6.x.</p> <p><a href="https://www.carbonblack.com/products/app-control/" rel="noopener" target="_blank">Carbon Black App Control</a> is a security solution designed to lock down critical systems and servers to prevent unauthorized changes in the face of cyber-attacks and ensure compliance with regulatory mandates such as PCI-DSS, HIPAA, GDPR, SOX, FISMA, and NERC.</p> <div class="ad_two clear"><center class="cf"><a href="https://go.thn.li/1-free-728-9" rel="nofollow noopener sponsored" target="_blank" title="Stack Overflow Teams"><img alt="Stack Overflow Teams" class="lazyload" src="https://thehackernews.com/images/-W-YXfspkl8I/YMt1op6vO6I/AAAAAAAA4Q4/SnWv_Gbl-RMg2BM3YaU9IL1sLek-JjiUACLcBGAsYHQ/s728-e100/free-ad-9-728.png"></a></center></div> <p>“A malicious actor with network access to the VMware Carbon Black App Control management server might be able to obtain administrative access to the product without the need to authenticate,” the California-based cloud computing and virtualization technology company <a href="https://www.vmware.com/security/advisories/VMSA-2021-0012.html" rel="noopener" target="_blank">said</a> in an advisory.</p> <p>CVE-2021-21998 is the second time VMware is addressing an authentication bypass issue in its Carbon Black endpoint security software. Earlier this April, the company fixed an incorrect URL handling vulnerability in the Carbon Black Cloud Workload appliance (<a href="https://thehackernews.com/2021/04/critical-auth-bypass-bug-found-in.html" rel="noopener" target="_blank">CVE-2021-21982</a>) that could be exploited to gain access to the administration API. </p> <p>That’s not all. VMware also patched a local privilege escalation bug affecting VMware Tools for Windows, VMware Remote Console for Windows (VMRC for Windows), and VMware App Volumes (CVE-2021-21999, CVSS score: 7.8) that could allow a bad actor to execute arbitrary code on affected systems.</p> <div class="ad_two clear"><center class="cf"><a href="https://go.thn.li/auth_300" rel="nofollow noopener sponsored" target="_blank" title="Enterprise Password Management"><img alt="Enterprise Password Management" class="lazyload" src="https://thehackernews.com/images/-SBDa0OwIyQY/YLy9M341QGI/AAAAAAAA4BM/m6-TrBrJenABekCqMu1Gp2XbmtAaeHd9ACLcBGAsYHQ/s300-e100/auth_300.jpg"></a></center></div> <p>“An attacker with normal access to a virtual machine may exploit this issue by placing a malicious file renamed as ‘openssl.cnf’ in an unrestricted directory which would allow code to be executed with elevated privileges,” VMware <a href="https://www.vmware.com/security/advisories/VMSA-2021-0013.html" rel="noopener" target="_blank">noted</a>.</p> <p>VMware credited Zeeshan Shaikh (@bugzzzhunter) from NotSoSecure and Hou JingYi (@hjy79425575) of Qihoo 360 for reporting the flaw.</p> <p></p> <p>The post <a rel="nofollow" href="https://patabook.com/technology/2021/06/27/critical-auth-bypass-bug-affects-vmware-carbon-black-app-control/">Critical Auth Bypass Bug Affects VMware Carbon Black App Control</a> appeared first on <a rel="nofollow" href="https://patabook.com/technology">Patabook Technology</a>.</p>
source https://patabook.com/blogs/100023/Critical-Auth-Bypass-Bug-Affects-VMware-Carbon-Black-App-Control
Subscribe to:
Post Comments (Atom)
Antifa Groups Charged with Violently Countering California ‘Patriot March’
Prosecutors have charged approximately seven individuals, described as self-identified anti-fascists, regarding eight alleged assaults in Ja...
-
Prosecutors have charged approximately seven individuals, described as self-identified anti-fascists, regarding eight alleged assaults in Ja...
-
Katy Perry and Orlando Bloom giggled their way down the red carpet on Saturday night at the Academy Museum of Motion Pictures Gala in Los An...
-
Will Halloween Ends Really Be The Last Of The Franchise? That brings us to one final, but ultimate question. Should Halloween Ends end the f...
No comments:
Post a Comment