<img height="1" width="1" style="display:none;" alt="" src="https://px.ads.linkedin.com/collect/?pid=1732033&amp;fmt=gif">
Skip to content
All posts

Emergency Advisory: VMware Vulnerabilities

Editor's note, October 2026: This advisory was first published on 19 May 2022 and describes CISA Emergency Directive 22-03 as it stood then. The vendor landscape has changed since. Broadcom completed its acquisition of VMware in November 2023, and VMware's end-user computing business, including Workspace ONE Access, became the independent company Omnissa in July 2024; the product is now called Omnissa Access. VMware Identity Manager, vRealize Automation (later renamed VMware Aria Automation) and VMware Cloud Foundation stayed with Broadcom, which now publishes VMware security advisories on its support portal. CVE-2022-22954 and CVE-2022-22960 remain listed in CISA's Known Exploited Vulnerabilities catalog; for CVE-2022-22954, CISA records known use in ransomware campaigns. How ISEC7 SPHERE monitors vulnerabilities today is described on the ISEC7 SPHERE page.

The Cybersecurity and Infrastructure Security Agency (CISA) has issued an emergency directive regarding vulnerabilities in VMware products.

On Wednesday, May 18, 2022, VMware released an update for two newly identified vulnerabilities, CVE-2022-22972 and CVE-2022-22973, affecting the following products: VMware Workspace ONE Access (Access), VMware Identity Manager (vIDM), VMware vRealize Automation (vRA), VMware Cloud Foundation, and vRealize Suite Lifecycle Manager.

According to the directive, CISA expects threat actors to quickly develop a capability to exploit these newly released vulnerabilities in the impacted VMware products. This already happened with two earlier vulnerabilities in the same products, CVE-2022-22954 and CVE-2022-22960: VMware released an update for them on April 6, 2022, and according to CISA, threat actors reverse engineered that update and began exploiting unpatched instances within 48 hours.

Taken together, the four vulnerabilities let attackers trigger a server-side template injection that may result in remote code execution (CVE-2022-22954), escalate privileges to 'root' (CVE-2022-22960 and CVE-2022-22973), and obtain administrative access without the need to authenticate (CVE-2022-22972).

"These vulnerabilities pose an unacceptable risk to federal network security," said CISA Director Jen Easterly. "CISA has issued this Emergency Directive to ensure that federal civilian agencies take urgent action to protect their networks. We also strongly urge every organization – large and small – to follow the federal government's lead and take similar steps to safeguard their networks."

Required actions

All Federal Civilian Executive Branch agencies must complete the following actions.

By 5:00 PM EDT on Monday, May 23, 2022

  1. Enumerate all instances of impacted VMware products (VMware Workspace ONE Access, VMware Identity Manager, VMware vRealize Automation, VMware Cloud Foundation, and vRealize Suite Lifecycle Manager) on agency networks.
  2. For all instances of impacted VMware products enumerated in required action 1, either deploy updates per VMware Security Advisory VMSA-2022-0014 or remove them from the agency network until the update can be applied. Where updates are not available because products are unsupported by the vendor (e.g., end of service, end of life), unsupported products must be immediately removed from agency networks.
  3. Additionally, for all instances of impacted VMware products that are accessible from the internet, assume compromise, immediately disconnect them from the production network, and conduct threat hunt activities as outlined in CISA advisory AA22-138B. Any anomalies identified must be reported to CISA immediately. Agencies may reconnect these products to their networks only after threat hunt activities are complete with no anomalies detected and updates are applied.

By 12:00 PM EDT on Tuesday, May 24, 2022

  1. Report the status of all instances enumerated in required action 1 into CyberScope using CISA's reporting template.

How ISEC7 can help

Whether you work in the Federal Civilian Executive Branch or in the private sector, the question is the same: which versions are running where, and which of them have known vulnerabilities? ISEC7 SPHERE compares the versions in your environment with the National Vulnerability Database (NVD) and raises an alert when a CVE becomes known for a version in use, so the right people can start remediation.

Fast patching is what separates a published vulnerability from a successful attack. We looked at that in Security Breach: Patch or Clash, and a comparable case from the same months is described in Understanding the Log4j Vulnerability. For a more recent advisory on a mobile management platform, read our public security announcement on Ivanti EPMM vulnerabilities.

Questions about vulnerabilities in your infrastructure or about how to strengthen it in general? Our endpoint security team is happy to help. Contact us.