Skip to content

Defense Digests

VMware Workspace ONE UEM Console Vulnerability

Dataprise Defense Digest 550x550

Table of content

EXECUTIVE SUMMARY

On December 16th 2021, VMware published a known vulnerability in their Workspace ONE UEM Console that if exploited successfully, would grant a malicious actor access to sensitive data.

Workspace ONE Unified Endpoint Management (ONE UEM) is a VMware solution for over-the-air remote management of desktops, mobile, rugged, wearables, and IoT devices.

This vulnerability affects both, on-prem and SAAS versions of the product. VMware has catalogued this vulnerability as Critical (9.1/10) and encourages immediate remediation by updating the affected products to the newest version, and/or following mitigation workaround procedures outlined below (see MITIGATION).

Dataprise Defense Digest

ID: D3-2021-0016-1

Severity: 9.1 (Critical)

Published: December 17, 2021

  

IMPACT

Precise impact analysis has not been released by VMware, but depending on the deployed integration level, malicious actors may be able to gain access to credentials, emails, phone numbers, account information, files, organizational structures, etc.

DETAILED ANALYSIS

Very few details have been released up until the writing of this article. However, it is known that this vulnerability can be abused without user interaction (automated attacks), allowing to fully bypass authentication on vulnerable systems, granting an unknown level of access to information  contained within the system, external connectors or endpoints managed by it.

INDICATORS OF COMPROMISE:

Vulnerable versions are outlined in the chart below, to check your console version:
– Log in to your dashboard, click on “about” and read the version information.


Impacted Version

Fixed Version

2109 Workspace ONE UEM patch 21.9.0.13 and above
2105 Workspace ONE UEM patch 21.5.0.37and above
2102 Workspace ONE UEM patch 21.2.0.27and above
2101 Workspace ONE UEM patch 21.1.0.27 and above
2011 Workspace ONE UEM patch 20.11.0.40and above
2010 Workspace ONE UEM patch 20.10.0.23 and above
2008 Workspace ONE UEM patch 20.8.0.36and above
2007 Workspace ONE UEM patch 20.7.0.17 and above




MITIGATION

The recommended course of action is to follow upgrade & update procedures if possible.

In case an update is not possible, VMware has outlined the following steps as a workaround:

[Resolved] CRSVC-25521 – Workspace ONE UEM – Guidance for addressing CVE-2021-22054 (87167) (vmware.com)

SOURCES

 

View all Dataprise Defense Digests here.

Recent Tweets

INSIGHTS

Learn about the latest threats and vulnerabilities with our D3 alerts.

Subscribe to get real-time notifications when a new Dataprise Defense Digest is published.