VMWare has issued a latest security advisory VMSA-2016-0013, which addresses two critical vulnerabilities of VMWare products – CVE-2016-5335 and CVE-2016-5336.
These are severe vulnerabilities that affect VMware Identity Manager and vRealize Automation software.
VMware vRealize Automation tool vRA is used in cloud environment to automate the delivery of infrastructure, applications and IT services.
VMware Identity Manager vIDM is used for application provisioning, conditional access controls and Single Sign-On (SSO) for cloud and mobile applications.
What is local privilege escalation vulnerability – CVE-2016-5335?
Every user account in a software application has a certain set of privileges assigned with it. A lower level user account will have only a limited set of privileges compared to a higher level account.
But a design flaw in the software helps the attacker, who gains access to a low privilege account, to obtain higher access. This is called a local privilege escalation vulnerability.
Local privilege escalation (CVE-2016-5335) can result in hackers gaining super user access and performing unauthorized actions in the system or accessing confidential information.
As a result, this vulnerability is a very critical one and the fix has to be done immediately to avoid compromising your data.
What is remote code execution vulnerability – CVE-2016-5336?
Remote code execution refers to executing arbitrary code from one machine on another machine, by accessing it via any exploits.
The hackers scan for open ports or vulnerable accounts in the applications and gain access to them. With this access, they can execute malicious code in the system.
Malicious remote code execution can lead to hackers gaining access to user’s privileges and obtaining critical information from your system.
To safeguard your information and system, it is critical to fix this vulnerability.
Are you vulnerable?
Local privilege escalation (CVE-2016-5335) reportedly affects both vIDM 2.x and vRA 6.x and 7.0.x versions of VMWare products.
If you are using VMWare cloud product such as VMware Workspace and are running these versions of software, your risk is very severe and need immediate fix.
Remote code execution vulnerability (CVE-2016-5336) only affects vRA 7.0.x products. The port 40002 in the nodes are exploited to gain access to the application.
However, the exploit is an important one and require immediate fix.
What’s the permanent fix?
The permanent fix recommended by VMWare is to update vIDM to version 2.7 and vRA to version 7.1 as soon as possible.
Until you can upgrade, there is a workaround for remote code execution vulnerability (CVE-2016-5336), that can be applied for vRA 7.0.x products.
How to implement the workaround?
The solution is to block access to port 40002 of the nodes in the High Availability cluster using iptables firewall.
iptables -A INPUT -p tcp --dport 40002 -j DROP
Before blocking all connections to the port from outside, it is important to allow access from other nodes in the cluster for proper functioning.
In short..
Today we’ve seen how we perform workaround for VMWare vulnerabilities CVE-2016-5335 and CVE-2016-5336 in cloud management hosting.
Our 24/7 security expert team keeps track of all the emerging vulnerabilities and this helps us to implement the fixes promptly in our clients’ servers before a hack occurs.
We also perform periodic server audits and pro-active server management services to secure the servers and protect them from hacks or exploits.
Bobcares helps online businesses of all sizes achieve world-class security and uptime, using tried and tested solutions. If you’d like to know how to make your server more reliable, we’d be happy to talk to you.
0 Comments