HomeSecurityVMware: Update Horizon servers against Log4j

VMware: Update Horizon servers against Log4j

VMware is urging its customers to patch critical Log4j security vulnerabilities, which affect VMware Horizon servers that are exposed to the Internet and are the target of ongoing attacks.

VMware

See also: AvosLocker ransomware: Linux version targets VMware ESXi servers

After successful exploitation, threat actors deploy custom webshells to the VM Blast Secure Gateway service to gain access to organizations' networks.

This allows them to carry out various malicious activities, such as data extraction and deployment of additional malware payloads, such as ransomware.

Microsoft also warned two weeks ago about a malicious actor from China, known as DEV-0401, who deploys Night Sky on VMware Horizon servers exposed to the Internet, using Log4Shell exploits.

"Even with VMware Security Alerts and ongoing efforts to communicate directly with customers, we continue to see that some companies have not applied the patch," said Kerry Tuttle, VMware's Director of Corporate Communications.

See also: Vulnerability in VMware vCenter is still exploitable

Log4j

“Customers who have not applied either the patch or the latest solution provided in VMware's security advisory are at risk of being compromised—or may have already been compromised—by malicious users who are exploiting the Apache Log4shell vulnerability to actively compromise unpatched Horizon.“

VMware's call for action follows a similar warning issued last week by the Netherlands' National Cyber ​​Security Center (NCSC), urging Dutch organizations to remain vigilant against the ongoing threats posed by Log4j attacks.

The Dutch government agency warned that malicious actors will continue to look for vulnerable servers that they can compromise in targeted attacks and asked organizations to implement Log4j security updates or mitigation measures where necessary.

See also: State-sponsored hackers attack Log4j via new PowerShell backdoor

There are tens of thousands of VMware Horizon servers exposed to the Internet, all of which need to be patched against Log4j.

Log4j (including Log4Shell) security flaws are a very attractive attack vector for state-sponsored and financially motivated attackers, as this open-source Apache logging library is used in software products from dozens of vendors.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS