VMware Workspace One Access, Access Connector, Identity Manager, and Identity Manager Connector address have a command injection vulnerability.
Published: 2020-12-09
The National Security Agency warns that Russian state-sponsored threat actors are exploiting an important VMware vulnerability in the wild. Background On December 7, the National Security Agency (NSA) published a cybersecurity advisory regarding in-the-wild exploitation, by Russian state-sponsored threat actors, of a vulnerability in several VMware products.
https://www.tenable.com/blog/vmware-patches-multiple-vulnerabilities-in-workspace-one-vmsa-2022-0011
https://www.tenable.com/cyber-exposure/2020-threat-landscape-retrospective
https://media.defense.gov/2020/Dec/07/2002547071/-1/-1/0/CSA_VMWARE%20ACCESS_U_OO_195076_20.PDF
https://www.vmware.com/security/advisories/VMSA-2020-0027.html