U.S. Cybersecurity and Infrastructure Security Agency (CISA): Companies should immediately patch or remove VMware products affected by recently disclosed critical flaws.
See also: CISA in organizations: Fix the WatchGuard bug

The drastic measure of removing products if they cannot be patched is based on the previous exploitation of critical VMware flaws within 48 hours of disclosure, according to CISA.
VMware disclosed on Wednesday, May 18, multiple security flaws in VMware Workspace ONE Access (Access), VMware Identity Manager (vIDM), VMware vRealize Automation (vRA), VMware Cloud Foundation, and vRealize Suite Lifecycle Manager.
The vulnerabilities are tracked as CVE-2022-22972 and CVE-2022-22973, which are respectively an authentication bypass with a severity rating of 9.8 out of 10 and a local privilege escalation vulnerability with a rating of 7.8.
See also: CISA: Attackers exploit flaw in Windows Print Spooler
An attacker with network access to the management user interface could access it without requiring a password, VMware warns in an advisory.
Patches are available and VMware is urging customers to apply them or mitigate the issues immediately, warning in a separate blog post that "the implications of this vulnerability are severe.".
CISA told U.S. to immediately patch or remove affected products based on the near-immediate and widespread exploitation of two VMware flaws – CVE-2022-22954 and CVE-2022-22960 – in the same products in April.
VMware released patches for these in April, but attackers quickly reversed the patches and bundled them together for exploitation.
Security firm Rapid7 observed active exploitation on April 12, six days after VMware released patches. Shortly thereafter, several public proof-of-concept exploits were used to install coin miners on vulnerable systems. The attackers combined CVE-2022-22954 (a server-side template injection issue affecting VMware Workspace ONE Access and Identity Manager) with CVE-2022-22960 (a local privilege escalation bug) to escalate to root privileges.

CISA issued an emergency directive requiring federal agencies to immediately patch the April VMware flaws, as it had done with the Apache Log4j “Log4Shell” flaws.
The security authority has issued the same guidance to federal agencies about the latest VMware flaws, noting that the flaws “pose a very serious risk” to federal civilian agencies.
See also: CISA: 7 New Security Flaws Vulnerable to Attacks
Cybersecurity authorities from other nations have not issued advisories regarding VMware's latest flaws. CISA, however, recommends that all organizations patch them quickly if vulnerable systems are accessible from the Internet. VMware has published mitigation steps for some of the affected products.
Information source: zdnet.com
