News
NPCC

CISA Issued Emergency Directive to Mitigate VMware Vulnerabilities

On May 18, 2022, CISA issued Emergency Directive 22-03 to mitigate VMware vulnerabilities. Threat actors are exploiting certain versions of the following VMware products: VMware Workspace ONE Access (Access), VMware Identity Manager (vIDM), VMware vRealize Automation (vRA), VMware Cloud Foundation, and vRealize Suite Lifecycle Manager. On May 18, 2022, VMware also released an update for two new vulnerabilities (CVE-2022-22972 and CVE-2022-22973).

The Emergency Directive only requires Federal Civilian Executive Branch agencies to update or remove the affected VMware products from their environments. It is recommended that organizations evaluate their exposure to these vulnerabilities and determine the appropriate mitigation actions as soon as possible.

CISA Link: CISA EMERGENCY DIRECTIVE 22-03 MITIGATE VMWARE VULNERABILITIES

CISA Link: CISA Alert (AA22-138B) Threat Actors Chaining Unpatched VMware Vulnerabilities for Full System Control

VMware Link: VMware Advisory VMSA-2022-0014

VMware Link: VMware Advisory VSMSA-2022-0011.1

TLP: WHITE

View attachmentView attachment
Previous Article
Next Article

NPCC is dedicated to the continued reliability of the bulk power system in Northeastern North America