VMware has released security updates to address three critical vulnerabilities in Workspace ONE Assist. These vulnerabilities could allow remote attackers to bypass authentication and elevate privileges to administrator level.
See also: 45,000 VMware ESXi servers just reached their end-of-life

Workspace ONE Assist is an enterprise-grade mobile device management solution that offers a wide range of features and benefits. With Workspace ONE Assist, you can manage all your mobile devices from a single console, deploy apps and updates remotely, and enforce security policies to keep data safe. You can also use Workspace ONE Assist to monitor device usage and troubleshoot issues remotely.
The three CVEs – 2022-31685 (authentication bypass), CVE-2022-31686 (broken authentication method), and CVE-2022-31687 (broken authentication check) – have received a CVSSv3 score of 9.8/10.
Malicious individuals without special skills can exploit these vulnerabilities to escalate their privileges without requiring help from users. These are attacks that do not require much work.
According to description , a "malicious actor with network access" could potentially bypass authentication and gain administrative control of the application.
See also: VMware vCenter Server bug revealed last year still hasn't been fixed
The company today released Workspace ONE Assist 22.10 (89993) for Windows customers , which fixes the bugs.

VMware also patched a cross-site scripting (XSS) vulnerability (CVE-2022-31688), which allows attackers to inject javascript into the target user's window, as well as a session repair vulnerability (CVE-2022 31689) that allows authentication after obtaining a valid session token.
VMware has patched all the vulnerabilities discovered and reported by Jasper Westerman, Jan van der Put, Yanick de Pater and Harm Blankers of REQON IT-Security.
VMware has warned administrators about another critical security flaw that could allow unauthorized attackers to gain administrator privileges. This authentication bypass security issue affected VMware Workspace ONE Access, Identity Manager , and vRealize Automation.
Exactly one week after the company's announcement, the exploit for the proof-of-concept was leaked online .This came to light after the researcher who discovered and reported the vulnerability shared his own PoC exploit.
See also: New malware targets VMware for hypervisor-level espionage
Last May, VMware patched another critical bypass vulnerability (CVE-2022-22972), which is quite similar to the one described in this advisory. Bruno López from Innotec Security originally discovered it in Workspace ONE Access, vIDM, and vRealize Automation.
