CISA Issued Emergency Directive to Mitigate VMware Vulnerabilities
On May 18, 2022, CISA issued Emergency Directive 22-03 to mitigate VMware vulnerabilities. Threat actors are exploiting certain versions of the following VMware products: VMware Workspace ONE Access (Access), VMware Identity Manager (vIDM), VMware vRealize Automation (vRA), VMware Cloud Foundation, and vRealize Suite Lifecycle Manager. On May 18, 2022, VMware also released an update for two new vulnerabilities (CVE-2022-22972 and CVE-2022-22973).
The Emergency Directive only requires Federal Civilian Executive Branch agencies to update or remove the affected VMware products from their environments. It is recommended that organizations evaluate their exposure to these vulnerabilities and determine the appropriate mitigation actions as soon as possible.
CISA Link: CISA EMERGENCY DIRECTIVE 22-03 MITIGATE VMWARE VULNERABILITIES
VMware Link: VMware Advisory VMSA-2022-0014
VMware Link: VMware Advisory VSMSA-2022-0011.1
TLP: WHITE