SecPod

Learn Search

Search across all Learn content

← Back to Security Research
VMware Products Under Active Attack Through a Critical Zero-Day Vulnerability

VMware Products Under Active Attack Through a Critical Zero-Day Vulnerability

VMware has released security updates to fix a critical vulnerability that is being exploited in the wild. According to the advisory, CVE-2020-4006 is a command injection bug, and attackers can take control of the system once exploited. This fix supersedes an initial workaround released by VMware in ...

Dec 7, 2020By Obaid R2 min read

VMware has released security updates to fix a critical vulnerability that is being exploited in the wild. According to the advisory, CVE-2020-4006 is a command injection bug, and attackers can take control of the system once exploited. This fix supersedes an initial workaround released by VMware in late November, a temporary fix while the company releases a permanent fix for the bug. Affected products include VMware Workspace One Access, Access Connector, Identity Manager, and Identity Manager Connector running on either Windows or Linux platforms.

CVE-2020-4006 Details

According to advisory VMSA-2020-0027.2.

““A malicious actor with network access to the administrative configurator on port 8443 and a valid password for the configurator admin account can execute commands with unrestricted privileges on the underlying operating system””

Although an attacker must have credentials beforehand to execute commands, which can be obtained by other methods such as brute-force, due to the above reasons, VMware updated the CVSS 3.x severity rating for this CVE from “critical” to “important” since the password itself is needed to proceed.

NSA released a security bulletin which states:

““The exploitation via command injection led to the installation of a web shell and follow-on malicious activity where credentials in the form of SAML authentication assertions were generated and sent to Microsoft Active Directory Federation Services (ADFS), which in turn granted the actors access to protected data.””

NSA also stressed the importance of properly configured servers that runs authentications for secure operation and integration. Otherwise, SAML assertions could be forged, granting access to numerous resources. SAML stands for Security Assertion Markup Language, an open standard that allows identity providers (IdP) to pass authorization credentials to service providers (SP).

Affected Softwares and OS

Affected products according to VMware advisory VMSA-2020-0027.2

  • VMware Workspace One Access 20.01, 20.10 (Linux)
  • VMware Identity Manager 3.3.3, 3.3.2, 3.3.1 (Linux)
  • VMware Identity Manager Connector 3.3.2, 3.3.1 (Linux)
  • VMware Identity Manager Connector 3.3.3, 3.3.2, 3.3.1 (Windows)
  • VMware Cloud Foundation 4.x (Linux and Windows)
  • vRealize Suite Lifecycle Manager 8.x (Linux and Windows)

Solution

VMware has already released a patch to fix this critical vulnerability in the wake of exploitations in the wild. VMware has advised updating your affected systems to the latest version as soon as possible. SanerNow software deployment capability can be used to install executables/scripts.

Featured Posts

Open CVE-2023-49105: The ownCloud Authentication Flaw That Exposed Sensitive Credentials
CVE-2023-49105: The ownCloud Authentication Flaw That Exposed Sensitive Credentials

CVE Research

CVE-2023-49105: The ownCloud Authentication Flaw That Exposed Sensitive Credentials

Sep 25, 2026

Open Patch Analysis & Exploitation Timeline: RouterOS SSH Attacks Predate Production Fixes in CISA's September 10, 2026 KEV Additions
Patch Analysis & Exploitation Timeline: RouterOS SSH Attacks Predate Production Fixes in CISA's September 10, 2026 KEV Additions

CVE Research

Patch Analysis & Exploitation Timeline: RouterOS SSH Attacks Predate Production Fixes in CISA's September 10, 2026 KEV Additions

Two MikroTik RouterOS CVEs entered CISA KEV seven days after production fixes. Dated reporting places SSH-chain exploitation involving CVE-2026-86060 at least one calendar day before those releases; no comparable start date is established for CVE-2026-67277.

Sep 25, 2026

Open Patch Analysis & Exploitation Timeline: A Day-Old Chrome Bug and an Eight-Month-Old Fortinet Flaw Share the Same KEV Batch
Patch Analysis & Exploitation Timeline: A Day-Old Chrome Bug and an Eight-Month-Old Fortinet Flaw Share the Same KEV Batch

CVE Research

Patch Analysis & Exploitation Timeline: A Day-Old Chrome Bug and an Eight-Month-Old Fortinet Flaw Share the Same KEV Batch

Four vulnerabilities added to CISA’s KEV catalog on September 9, 2026 show widely different timelines between public disclosure and formal exploitation-based prioritization, ranging from one day to 239 days.

Sep 24, 2026

Open TA412/APT31: Mapping Threat Actor Patterns to CVE Exploitation Chains

TA412/APT31: Mapping Threat Actor Patterns to CVE Exploitation Chains

CVE Research

TA412/APT31: Mapping Threat Actor Patterns to CVE Exploitation Chains

A chronological look at how a long-running China-nexus espionage cluster evolved from server-side exploitation to a chained Chrome/Windows zero-day kit — and what that shift signals.

Sep 24, 2026