CISA Warns of Ongoing VMware VMscare

Share This Post

Back on April 6th, 2022, VMware released software updates and disclosed two vulnerabilities. The updates were intended to address (CVE-2022-22954 and CVE-2022-22960) which afflict VMware Workspace ONE Access, VMware Identity Manager (vIDM), vRealize Lifecycle Manager, vRealize Automation, and VMware Cloud Foundation products. Within 48 hours, those updates had been reverse engineered by sophisticated threat actors and those vulnerabilities were being actively exploited to enable privilege escalation and trigger a server-side template injection that can result in remote code execution.

On May 18th, 2022, VMware released software updates and disclosed two more fresh vulnerabilities for the same list of products. (CVE-2022-22972 and CVE-2022-22973) On the same day, the Cybersecurity and Infrastructure Security Agency (CISA) issued an emergency directive along with an alert that warns of threat actors chaining these four vulnerabilities to gain full system control.

In the week since, these most recent updates have again been reverse engineered, allowing attackers to obtain administrative access without needing to authenticate, and/or escalate privileges all the way to ‘root.’

For all the product versions affected and remediation procedures, visit: https://kb.vmware.com/s/article/88438



Reach out to our incident response team for help

More To Explore

Information Security News – 6/23/2025

Law Enforcement Takedowns Disrupt Cybercrimes Across the Globe Article Link: https://cyberscoop.com/cybercrime-crackdown-operation-endgame-operation-secure/   Microsoft 365 to Block File Access Via Legacy Auth by Default Article link:

Information Security News – 6/16/2025

Grocery Wholesale Giant United Natural Foods Hit by Cyberattack Article Link: https://www.bleepingcomputer.com/news/security/grocery-wholesale-giant-united-natural-foods-hit-by-cyberattack/ The Worsening Landscape of Educational Cybersecurity Article Link: https://blog.knowbe4.com/the-worsening-landscape-of-educational-cybersecurity Gov. Abbott Signs Texas

Do You Want to Shore Up Your Defenses?

We're opening our first round of threat hunting engagements to 100 organizations. Sign up or join the wait list here.