ZDI-23-841: VMware Aria Operations for Networks getNotifiedEvents Deserialization of Untrusted Data Remote Code Execution Vulnerability
Published Jun 8, 2023
·Updated
This vulnerability allows remote attackers to execute arbitrary code on affected installations of VMware Aria Operations for Networks. Authentication is required to exploit this vulnerability.
Affected Software
1 affected component
VMware Aria Operations for Networks
Event History
Jun 8, 2023
Advisory Published
05:00 AM
Data Sourced
05:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-23-841?
ZDI-23-841 has been assigned a critical severity level due to its potential to allow remote code execution.
2
How do I fix ZDI-23-841?
To remediate ZDI-23-841, apply the latest security patches provided by VMware for Aria Operations for Networks.
3
What are the risks associated with ZDI-23-841?
The risks of ZDI-23-841 include unauthorized remote code execution, which could lead to system compromise.
4
Who is affected by ZDI-23-841?
Organizations using affected installations of VMware Aria Operations for Networks are vulnerable to ZDI-23-841.
5
Is authentication required to exploit ZDI-23-841?
Yes, authentication is required to exploit the vulnerability ZDI-23-841.