Editor's note, October 2026: This advisory was first published on 19 May 2022 and describes CISA Emergency Directive 22-03 as it stood then. The vendor landscape has changed since. Broadcom completed its acquisition of VMware in November 2023, and VMware's end-user computing business, including Workspace ONE Access, became the independent company Omnissa in July 2024; the product is now called Omnissa Access. VMware Identity Manager, vRealize Automation (later renamed VMware Aria Automation) and VMware Cloud Foundation stayed with Broadcom, which now publishes VMware security advisories on its support portal. CVE-2022-22954 and CVE-2022-22960 remain listed in CISA's Known Exploited Vulnerabilities catalog; for CVE-2022-22954, CISA records known use in ransomware campaigns. How ISEC7 SPHERE monitors vulnerabilities today is described on the ISEC7 SPHERE page.
The Cybersecurity and Infrastructure Security Agency (CISA) has issued an emergency directive regarding vulnerabilities in VMware products.
On Wednesday, May 18, 2022, VMware released an update for two newly identified vulnerabilities, CVE-2022-22972 and CVE-2022-22973, affecting the following products: VMware Workspace ONE Access (Access), VMware Identity Manager (vIDM), VMware vRealize Automation (vRA), VMware Cloud Foundation, and vRealize Suite Lifecycle Manager.
According to the directive, CISA expects threat actors to quickly develop a capability to exploit these newly released vulnerabilities in the impacted VMware products. This already happened with two earlier vulnerabilities in the same products, CVE-2022-22954 and CVE-2022-22960: VMware released an update for them on April 6, 2022, and according to CISA, threat actors reverse engineered that update and began exploiting unpatched instances within 48 hours.
Taken together, the four vulnerabilities let attackers trigger a server-side template injection that may result in remote code execution (CVE-2022-22954), escalate privileges to 'root' (CVE-2022-22960 and CVE-2022-22973), and obtain administrative access without the need to authenticate (CVE-2022-22972).
"These vulnerabilities pose an unacceptable risk to federal network security," said CISA Director Jen Easterly. "CISA has issued this Emergency Directive to ensure that federal civilian agencies take urgent action to protect their networks. We also strongly urge every organization – large and small – to follow the federal government's lead and take similar steps to safeguard their networks."
All Federal Civilian Executive Branch agencies must complete the following actions.
Whether you work in the Federal Civilian Executive Branch or in the private sector, the question is the same: which versions are running where, and which of them have known vulnerabilities? ISEC7 SPHERE compares the versions in your environment with the National Vulnerability Database (NVD) and raises an alert when a CVE becomes known for a version in use, so the right people can start remediation.
Fast patching is what separates a published vulnerability from a successful attack. We looked at that in Security Breach: Patch or Clash, and a comparable case from the same months is described in Understanding the Log4j Vulnerability. For a more recent advisory on a mobile management platform, read our public security announcement on Ivanti EPMM vulnerabilities.
Questions about vulnerabilities in your infrastructure or about how to strengthen it in general? Our endpoint security team is happy to help. Contact us.