
VMware addresses critical security vulnerabilities in vRealize and logging products.
VMware has fixed a critical security vulnerability in its log analysis tool, VMware Aria Operations for Logs (formerly vRealize Log Insight), that allowed remote attackers to execute arbitrary code as root on compromised systems. The bug, tracked as CVE-2023-20864, is a deserialization vulnerability that can be exploited remotely by unauthenticated threat actors. VMware also released security updates for a second flaw (CVE-2023-20865) that enables remote attackers with administrative privileges to execute arbitrary commands as root. Both vulnerabilities were addressed with the release of VMware Aria Operations for Logs 8.12.