VMware Security Update – 14 May 2023

VMware has released a security update to fix multiple vulnerabilities across VMware Aria Operations (formerly vRealize Operations) and VMware Cloud Foundation.

addressed vulnerabilities could allow the authenticated attacker to gain elevated privileges on the affected system by sending a specially crafted request.

Sample of the addressed vulnerabilities:

VMware Aria Operations Privilege Escalation (CVE-2023-20877):

  • CVSS: 8.8
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: Low
  • User Interaction: None
  • Consequences: Gain Privileges

Affected Products:

  • VMware Aria Operations 8.6.x.
  • VMware Aria Operations 8.10.
  • VMware Aria Operations 8.12.
  • VMware Cloud Foundation 4.x.
Vulnerabilities
  • CVE-2023-20877
  • CVE-2023-20878
  • CVE-2023-20879
  • CVE-2023-20880
Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

VMware Security Advisory

References