VMware patches RCE Spring4Shell vulnerability on a wide range of products
VMware has released a number of security updates to patch remote code execution for a dangerous vulnerability called Spring4Shell in the company's virtual machine and cloud products.
The list of products affected by Spring4Shell is posted by VMware in the security warning that the company has just posted. For unpatched products, VMware also provides a temporary fix.
At this point, users should follow the security guidelines because Spring4Shell is being actively exploited by hackers.
Spring4Shell is a remote code execution (RCE) vulnerability tracked under code CVE-2022-22965. This vulnerability resides in the Spring Core Java framework and can be exploited without authentication, with a severity rating of 9.8 out of 10.
Since Spring Framework is widely deployed for Java application development, security analysts are concerned about large-scale attacks targeting the Spring4Shell vulnerability.
Worse still, this exploit (PoC) method was shared on GitHub before the patches were released. Although it was immediately removed, this exploit method was shared everywhere on the internet.
This critical vulnerability affects Spring MVC and Spring WebFlux applications running on JDK 9+. To exploit requires the application to run on Tomcat as a WAR implementation although the exact limitations are still under investigation.
Below are the affected VMware products:
- VMware Tanzu Application Service for VMs - versions 2.10 to 2.13.
- VMware Tanzu Operation Manager - version 2.8 to 2.9.
- VMware Tanzu Kubernetes Grid Integrated Edition (TKGI) - versions 1.11 to 1.13.
If you are using products with the above versions, you should update immediately to ensure that all vulnerabilities are fixed.
- Botnet Echobot spreads across a wide range, specifically targeting Oracle and VMware applications
- Intel will stop releasing patches for the Specter v2 security hole on some older CPUs
- VMware Fusion Pro is available for free for personal use
- Detect a critical flaw in VMware Cloud Director, which could pave the way for hackers to take control of enterprise servers
- VMware Workstation Pro - Download VMware Workstation Pro here
- Learn about patches
- Compare VMware Workstation Pro and VMware Workstation Player
- 'Printer Catastrophe' Vulnerability Threatens All Versions of Windows