PT-2021-3448 · Vmware · Vmware App Volumes+3

Bugzzzhunter

+1

·

Published

2021-06-22

·

Updated

2022-07-12

·

CVE-2021-21999

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions VMware Tools for Windows versions 11.x.y prior to 11.2.6 VMware Remote Console for Windows versions 12.x prior to 12.0.1 VMware App Volumes versions 2.x prior to 2.18.10 VMware App Volumes version 4 prior to 2103
Description The issue is related to a local privilege escalation vulnerability. An attacker with normal access to a virtual machine may exploit this by placing a malicious file renamed as openssl.cnf in an unrestricted directory, allowing code to be executed with elevated privileges. The vulnerability is also associated with an uncontrolled search path element.
Recommendations For VMware Tools for Windows versions 11.x.y prior to 11.2.6, update to version 11.2.6 or later. For VMware Remote Console for Windows versions 12.x prior to 12.0.1, update to version 12.0.1 or later. For VMware App Volumes versions 2.x prior to 2.18.10, update to version 2.18.10 or later. For VMware App Volumes version 4 prior to 2103, update to version 2103 or later. As a temporary workaround, consider restricting access to unrestricted directories to minimize the risk of exploitation. Avoid using the openssl.cnf file in vulnerable configurations until the issue is resolved.

Fix

LPE

Uncontrolled Search Path Element

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-03308
CVE-2021-21999
ZDI-21-754

Affected Products

Vmware App Volumes
Vmware Remote Console For Windows
Vmware Tools
Vmware Tools For Windows