VMware addresses critical security vulnerabilities in vRealize and logging products.

1 min read
Source: BleepingComputer
VMware addresses critical security vulnerabilities in vRealize and logging products.
Photo: BleepingComputer
TL;DR Summary

VMware has fixed a critical security vulnerability in its log analysis tool, VMware Aria Operations for Logs (formerly vRealize Log Insight), that allowed remote attackers to execute arbitrary code as root on compromised systems. The bug, tracked as CVE-2023-20864, is a deserialization vulnerability that can be exploited remotely by unauthenticated threat actors. VMware also released security updates for a second flaw (CVE-2023-20865) that enables remote attackers with administrative privileges to execute arbitrary commands as root. Both vulnerabilities were addressed with the release of VMware Aria Operations for Logs 8.12.

Share this article

Reading Insights

Total Reads

0

Unique Readers

10

Time Saved

1 min

vs 2 min read

Condensed

73%

32889 words

Want the full story? Read the original article

Read on BleepingComputer