Thread Rating:
  • 0 Vote(s) - 0 Average
  • 1
  • 2
  • 3
  • 4
  • 5
Share Post: Reddit Facebook
VMware addresses Remote Code Execution issue in View Planner
#1
Quote:[b]VMware released a security patch for a remote code execution vulnerability that affects the VMware View Planner product.[/b]
 
VMware released a security patch for a remote code execution flaw, tracked as CVE-2021-21978, that affects the VMware View Planner.
 
The View Planner is a free tool for Performance Sizing and Benchmarking of Virtual Desktop Infrastructure environments.
 
The vulnerability was reported Positive Technologies researcher Mikhail Klyuchnikov.
 
The company fixed the CVE-2021-21978 vulnerability with the release of version 4.6 Security Patch 1 on March 2. The vulnerability received a CVSS score of 8.6.
“A vulnerability in VMware View Planner was privately reported to VMware. An update is available to remediate this vulnerability in affected VMware products.” reads te [color=var(--theme-link_a)]advisory published by the company. “Improper input validation and lack of authorization leading to arbitrary file upload in logupload web application. An unauthorized attacker with network access to View Planner Harness could upload and execute a specially crafted file leading to remote code execution within the logupload container.”[/color]
 
The issue is caused by the improper input validation and the lack of authorization that could allow an attacker to upload specially crafted files in logupload web application. The vulnerability could be exploited only by an attacker with network access.
 
VMware recommends installing the security patch, but it not known if the flaw has been exploited in attacks in the wild.
 


Source
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  Vulnerabilities in WatchGuard, Panda Security Products Lead to Code Execution mrtrout 0 476 02-04-2024 , 06:49 AM
Last Post: mrtrout
  Broadcom's VMware acquisition cleared Broadcom’s $69 billion acquisition of VMware. mrtrout 0 1,543 07-19-2023 , 04:06 PM
Last Post: mrtrout
  VMware warns of critical vRealize flaw exploited in attacks mrtrout 0 399 06-21-2023 , 02:00 AM
Last Post: mrtrout
  Firefox 98.0.2 fixes a crash on Windows, an add-ons issue, and more Mohammad.Poorya 0 1,582 03-23-2022 , 03:09 PM
Last Post: Mohammad.Poorya
  VMware Patches Important Bug Affecting ESXi, Workstation and Fusion Products mrtrout 0 542 01-06-2022 , 07:26 PM
Last Post: mrtrout

Forum Jump:


Users browsing this thread: 1 Guest(s)