VMware Released Security Updates for Critical Remote Code Execution Vulnerability

VMware security updates published for its AirWatch Agent that affected by critical remote code execution vulnerability.

VMware is a virtualization software which is installed on the physical server to allow for multiple virtual machines (VMs) to run on the same physical server.

This critical vulnerability discovered in VMware AirWatch Agent a division of virtualization vendor VMware.

It helps IT administrators deploy, secure and manage mobile devices, applications, and data, as well as Windows 10 and Apple Mac computers.

AirWatch Agent RCE Affected Platform

This Critical RCE vulnerability affects both VMware AirWatch Agent for Android (A/W Agent) & VMware AirWatch Agent for Windows Mobile (A/W Agent).

According to VMware, Android and Windows Mobile devices contain a remote code execution vulnerability in real time File Manager capabilities.

Also, this vulnerability leads to unauthorized creation and execution of files in the Agent sandbox also in other publicly accessible directories.

This RCE vulnerability leads to a remote attacker could exploit this vulnerability to take control of an affected system.

Mitigations

Users are recommended to update AirWatch Agent for Android 8.2 and AirWatch Agent for Windows Mobile 6.5.2 to mitigate the vulnerabilities.

Balaji

BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security.

Recent Posts

Hackers Exploit Cloudflare Tunnel Infrastructure to Deploy Multiple Remote Access Trojans

The Sekoia TDR (Threat Detection & Research) team has reported on a sophisticated network infrastructure…

4 hours ago

Threat Actors Leverage npm and PyPI with Impersonated Dev Tools for Credential Theft

The Socket Threat Research Team has unearthed a trio of malicious packages, two hosted on…

4 hours ago

Hackers Exploit Legitimate Microsoft Utility to Deliver Malicious DLL Payload

Hackers are now exploiting a legitimate Microsoft utility, mavinject.exe, to inject malicious DLLs into unsuspecting…

6 hours ago

Cybercriminals Exploit Network Edge Devices to Infiltrate SMBs

Small and midsized businesses (SMBs) continue to be prime targets for cybercriminals, with network edge…

6 hours ago

Criminal IP to Showcase Advanced Threat Intelligence at RSAC™ 2025

Joining Criminal IP at Booth S-634 | South Expo, Moscone Center | April 28 –…

6 hours ago

TP-Link Router Vulnerabilities Allow Attackers to Execute Malicious SQL Commands

Cybersecurity researchers have uncovered critical SQL injection vulnerabilities in four TP-Link router models, enabling attackers…

7 hours ago