4.9 • 696 Ratings
🗓️ 19 May 2022
⏱️ 7 minutes
🧾️ Download transcript
Click on a timestamp to play from that location
0:00.0 | Hello, welcome to the Thursday, May 19, 2020 edition of the Sandsenet Storm Center's Stormcast. My name is Johannes Ulrich, |
0:09.7 | and I'm recording from Jacksonville, Florida. Well, let's start with VMware today. We got another |
0:16.1 | critical war on ability that VMware patched the CBE 2020-9772. It's an off-occation bypass, |
0:26.7 | and it does affect VMware Workspace 1-AXX, Identity Manager, we realize automation. And VMware |
0:34.0 | did assign it a CVSSV3 base score of 9.8. |
0:40.3 | An attacker does need access to the user interface and will be able to gain administrative |
0:47.3 | access without the need for any of occasion. |
0:51.3 | So VMware does recommend that you apply the patch quickly. |
0:55.7 | No exploit yet as far as I know, |
0:57.8 | but of course they tend to come pretty quickly. |
1:01.5 | And the tricky part here is a little bit |
1:02.9 | that the vulnerable component here really |
1:04.7 | is the VMware Identity Manager. |
1:06.6 | So if you have this deployed with any other VMware products, you may also have an issue. |
1:14.8 | And talking about these vulnerabilities being exploited rather quickly in April, |
1:20.0 | VMware did publish security advisories that listed a number of different vulnerabilities, |
1:24.5 | including a server-side template injection issue, |
1:27.8 | essentially an arbitrary code execution vulnerability that could be exploited also via the web |
1:35.1 | interface. |
1:36.1 | Well, Barakuta is now reporting that this vulnerability is already being exploited, so definitely |
1:43.7 | patch now. |
1:44.9 | And applying this new patch should actually also fix this older vulnerability. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2025.