VMware Cloud Director CVE-2020-3956

Before anything else… if you haven’t patched your Cloud Director installations as per the below table… do it now! With that done, let’s continue. This VMware Security advisory was released on May 19th and related to a series of vulnerabilities in VMware Cloud Director. This was discovered by Citadelo, an Ethical Hacking company.

The vulnerability allows an attacker to gain access to sensitive data and take over control of private clouds within an entire infrastructure. The issue was that VMware Cloud Director does not properly handle input, leading to a code injection vulnerability. An authenticated actor may be able to send malicious traffic to VMware Cloud Director, which may lead to arbitrary remote code execution. This can be exploited through the HTML5- and Flex-based UIs, the API Explorer interface, and API access.

There is a quick workaround as described in this VMwareKB. Citadelo has an amazingly detailed blog on the exploit here, and they were able to perform the following actions using the code injection: Just to clarify at this stage, that this is not a negative post about VMware or Cloud Director in general; it’s clearly the best Cloud Management Platform in existence and has only gone from strength to strength over the past few years.

VMware provided quick fixes and patches in quick time. Exploits and vulnerabilities happen all the time on almost all software and hardware-based platforms, mainly just a case of them being discovered and exploited by the right people with wrong intentions to cause pain.

In my past life looking after a number of vCloud Director-based (and other IaaS) cloud platforms, there was always one thing that kept me up at night: a scenario where a malicious user somehow gained access through the exposed endpoints and wreaked havoc on tenancies and underlying management infrastructure. It was a situation that I always thought could be devastating and have no coming back from the business, as well as personal stigma and shame attached to myself as responsible for the operations and management of the platform.

I can almost say that this is not something I wanted hanging over my head and was happy to walk away from the responsibility when moving to Veeam. As much as I miss most elements of operating and managing a cloud hosting platform, the threat of decimation was not one I wanted to hang over my head. If you search around the internet, you will find many examples of Hosting and/or Software as a Service businesses that have been decimated after being exploited.

Generally speaking, the malicious user isn’t doing it for financial gain; there is usually a personal vendetta in play. The threat of insider attack is real and was also something I used to have to think about. To a certain extent, the insider attack threat can be as damaging as external attacks.

Lastly, mitigation needs to be your first line of defense. Locking down systems, tracking access, reducing attack surfaces while keeping track of exploits and vulnerability across all systems and platforms is not an easy task and often gets overlooked. We all like to think we are better than the next provider, but reality says otherwise… This is a critical reminder that no one is safe from potential attacks and it’s so important to be aware of any exploits reported and put in place strategies to mitigate them.