Russian state-sponsored hackers are actively exploiting a bug in some VMware endpoint and identity management products, according to a U.S. National Security Agency warning issued today.
VMware rolled out a patch for the command injection vulnerability, tracked as CVE-2020-4006, over the weekend. But, it first warned about the “important” security flaw, which affects some versions of its Workspace One Access, Access Connector, Identity Manager, and Identity Manager Connector late last month.
In its advisory, the NSA urged organizations to patch affected systems “as soon as possible,” and it specifically encouraged the National Security System, Department of Defense, and Defense Industrial Base network administrators “to prioritize mitigation of the vulnerability on affected servers.”
To exploit this vulnerability, an attacker must have access to the device’s management interface. This access can allow attackers to forge security assertion markup language (SAML) credentials to send seemingly authentic requests to gain access to protected data.
Gotta Getta Better PasswordAnd because this bug requires password-based access to the web-based management interface of the device, the NSA points out that “using a strong and unique password lowers the risk of exploitation. The risk is lowered further if the web-based management interface is not accessible from Internet.”
Chris Morales, head of security analytics at Vectra, which uses artificial intelligence to detect and hunt for cyber attackers, notes that “this is why granted access does not equate to trusted access,” because a hacker in Russia shouldn’t be granted access to enterprise and government servers in the U.S.
“This is an access compromise technique that requires the attacker already have access to the management web interface. Another layer, so to speak,” he wrote in an email. “While it sounds bad (it is), it does seem to be a bigger problem if the attacker has access to the management interface in the first place … It is important to observe how, where and when privilege access occurs to know when it is being used for malicious intent.”
Attackers Target Remote WorkersThe exploits also illustrate how attackers are taking targeting remote work platforms like VMware’s Workspace One products as government officials and company executives have shifted to remote work during the ongoing pandemic. A new report by McAfee, also published today, says cybercrime is a major global business that costs the world economy over $1 trillion, and the move to cloud services and remote work have massively expanded organizations’ threat surfaces.
The report specifically calls out Russia and says “the complex and close relationship between the state and organized crime makes it into a sanctuary for the most advanced cybercriminals.” While the Russian government allows these criminal groups to pursue financially motivated cyberattacks without fear of prosecution from law enforcement, in exchange “they are expected to use their skills to support the government’s interests.”
Comments