Vulnerability in Windows Domain Name System (DNS)
On July 14, 2020, Microsoft released a security update for the issue described in CVE-2020-1350 | Windows DNS Server Remote Code Execution...
24/7/365 Monitoring & Alerting
Compromise Assessments
Threat Hunting
Vulnerability Management
CMMC Preparation & Assessment
Cybersecurity Assurance Readiness (CSAR®/RMF Pro)
ATO/RMF Support
If you are concerned about a potential threat or are experiencing a breach, contact our 24/7/365 emergency hotline at 888-860-0452.
Sign up to receive our biweekly newsletter that covers what's happening in cybersecurity including news, trends, and thought leadership.
At our core, Ingalls is a company that strives to be helpful to our clients while continuously innovating and evolving our technology and solutions. Since 2010, we have been dedicated to building a team and product that can stay steps ahead of threats, attacks, and vulnerabilities in an ever-changing landscape.
This advisory specifically applies to the following VMware products:
Proofs-of-Concept exist in the wild for the RCE vulnerability.
• CVE-2021-21985 - CVSS Score of 9.8/10 (Critical)
• CVE-2021-21986 - CVSS Score of 6.5/10 (Moderate)
The best and quickest way to ensure protection is to apply the patches released by VMware. However, immediate patching is not possible you should disable the affected plugins by adding the following lines under the "pluginsCompatibility" element in your compatibility-matrix.xml file:
<PluginPackage id="com.vmware.vrops.install" status="incompatible"/>
<PluginPackage id="com.vmware.vsphere.client.h5vsan" status="incompatible"/>
<PluginPackage id="com.vmware.vrUi" status="incompatible"/>
<PluginPackage id="com.vmware.vum.client" status="incompatible"/>
<PluginPackage id="com.vmware.h4.vsphere.client" status="incompatible"/>
After adding these lines, stop and restart the “vsphere-ui” service. Organizations should review the criticality of these plugins before attempting this mitigation.
More information from VMWare on considerations for applying these patches can be found in this article.
On July 14, 2020, Microsoft released a security update for the issue described in CVE-2020-1350 | Windows DNS Server Remote Code Execution...
The Veeam Distribution Service installed on Veeam Backup & Replication servers runs on TCP 9380 with default settings, and allows unauthenticated...
It's important that organizations deploy last week's "Patch Tuesday" patches as soon as possible. These patches include several critical, high, and...