---
title: "NSA Warns that VMware Flaw is Being Actively Exploited, Fixes Available"
canonical: "https://www.virtcloudrocks.com/space/INFOSEC/blog/852338/NSA%20Warns%20that%20VMware%20Flaw%20is%20Being%20Actively%20Exploited%2C%20Fixes%20Available"
format: markdown
---
Article reposted from SANS NewsBites Vol. 22 Num. 096

   
The US National Security Agency (NSA) has issued a cybersecurity advisory, warning that Russian hackers are exploiting a command injection flaw in VMware Access and VMware identity Manager. The exploit allows attackers to install malware, access data, and maintain a persistent presence on vulnerable systems. VMware issued fixes for the flaw on Thursday, December 3.  
   
**Editor's Note**  
  
The attack relies on compromising the management interface, which runs on port 8443. The workaround disables configurator-managed settings changes. Apply the package updates now rather than the workaround and only make the management interface available to trusted systems, don’t expose it to the internet.  
  
**Read more in:**  
**- **[**media.defense.gov**](https://media.defense.gov/2020/Dec/07/2002547071/-1/-1/0/CSA_VMWARE%20ACCESS_U_OO_195076_20.PDF): Russian State-Sponsored Actors Exploiting Vulnerability in VMware® Workspace ONE Access Using Compromised Credentials (PDF)  
**- **[**kb.vmware.com**](https://kb.vmware.com/s/article/81754): HW-128524: CVE-2020-4006 for Workspace ONE Access, Identity Manager and Connector (81754)  
**- **[**www.vmware.com**](https://www.vmware.com/security/advisories/VMSA-2020-0027.html): Advisory | VMSA-2020-0027.2  
**- **[**arstechnica.com**](https://arstechnica.com/information-technology/2020/12/nsa-says-russian-state-hackers-are-using-a-vmware-flaw-to-ransack-networks/): NSA says Russian state hackers are using a VMware flaw to ransack networks  
**- **[**www.cyberscoop.com**](https://www.cyberscoop.com/nsa-russia-hackers-dod-vmware/): NSA warns of Russian government-backed hackers aiming at US defense sector targets  
**- **[**www.wired.com**](https://www.wired.com/story/nsa-warns-russia-attacking-vmware-remote-work-platforms/): The NSA Warns That Russia Is Attacking Remote Work Platforms  
**- **[**www.zdnet.com**](https://www.zdnet.com/article/nsa-warns-of-russian-state-sponsored-hackers-exploiting-vmware-vulnerability/): NSA warns of Russian state-sponsored hackers exploiting VMWare vulnerability  
**- **[**www.securityweek.com**](https://www.securityweek.com/vmware-patches-workspace-one-access-vulnerability-reported-nsa): VMware Patches Workspace ONE Access Vulnerability Reported by NSA  
**- **[**threatpost.com**](https://threatpost.com/vmware-fix-critical-zero-day-bug/161896/): VMware Rolls a Fix for Formerly Critical Zero-Day Bug  
**- **[**www.bleepingcomputer.com**](https://www.bleepingcomputer.com/news/security/vmware-fixes-zero-day-vulnerability-reported-by-the-nsa/): VMware fixes zero-day vulnerability reported by the NSA