VMware Security Advisory

VMware ESXi, Workstation, Fusion and vCloud Director Security Updates

VMware has released two new security advisories VMSA-2019-0004 (VMware vCloud Director for Service Providers update resolves a Remote Session Hijack vulnerability) and VMSA-2019-0005 (VMware ESXi, Workstation and Fusion updates address multiple security issues).

The advisories document the remediation of these critical issues:

  • VMware vCloud Director for Service Providers update resolves a Remote Session Hijack vulnerability in the Tenant and Provider Portals. Successful exploitation of this issue may allow a malicious actor to access the Tenant or Provider Portals by impersonating a currently logged in session.
  • VMware ESXi, Workstation and Fusion contain an out-of-bounds read/write vulnerability and a Time-of-check Time-of-use (TOCTOU) vulnerability in the virtual USB 1.1 UHCI (Universal Host Controller Interface). Exploitation of these issues requires an attacker to have access to a virtual machine with a virtual USB controller present. These issues may allow a guest to execute code on the host.
  • VMware Workstation and Fusion contain an out-of-bounds write vulnerability in the e1000 virtual network adapter. This issue may allow a guest to execute code on the host.
  • VMware Workstation and Fusion updates address an out-of-bounds write vulnerability in the e1000 and e1000e virtual network adapters. Exploitation of this issue may lead to code execution on the host from the guest but it is more likely to result in a denial of service of the guest.
  • VMware Fusion contains a security vulnerability due to certain unauthenticated APIs accessible through a web socket. An attacker may exploit this issue by tricking the host user to execute a JavaScript to perform unauthorized functions on the guest machine where VMware Tools is installed. This may further be exploited to execute commands on the guest machines.
Read More
VMUG Romania

VMUG Romania February Meeting Report

On 12 February 2019, VMUG Romania held its first meeting of this year in one of the best location we have seen so far: Journey Pub in Bucharest. More than 50 persons attended the full-day event. Two records here, one for the number of participants and the other for the event duration. Dell EMC and Bitdefender were the sponsors of this meeting.

My fellow leaders made me the honor of opening the meeting. After my short introduction, Razvan Ionescu made the announcement of the year in my opinion: the keynote speaker for VMUG Romania next meeting on 11 June 2019 will be Joe Baguley, VP and CTO VMware EMEA. Joe is an inspiring speaker, I’m confident we will have a lot to learn from him. You can watch Joe in few episodes of VMware Carpool Tech Talk. Mihai Huica then introduced a new tool we used for gathering feedback from audience.

Read More
VMUG Romania February Meeting

VMUG Romania February Meeting

Dell EMC

Four months after the previous VMUG Romania meeting, we invite you to a new event dedicated to VMware technologies. Journey Pub in Bucharest will be our host for 12 February 2019. We will have presentation sessions, demos, networking and hopefully some interesting announcements.

This is the first full-day meeting for VMUG Romania, so be patient till the end for a non-virtual craft beer tasting session.

Bitdefender

Next to VMware presentation (Cristian Radu – “Deep Dive VMware NSX-V”) and those of the sponsors Dell EMC (Cristian Stan – The Power of Hyper-Converged) and Bitdefender (Gabriel Mihai Mazarache – Security automation, performance, and response across multiple VMware clouds), we will have no less then 4 community sessions.

Read More
PowerCLI 11.1.0

PowerCLI 11.1.0 – More on Linux Side

During the last few days of December 2018, VMware released the 6th PowerCLI version of the year: PowerCLI 11.1.0. The coolest new features move around Site Recovery Manager:

  • Support for SRM module in MacOS and Linux
  • Support for Site Recovery Manager 8.1 API features
  • VMware.VimAutomation.Storage module received updates on 2 cmdlets: Get-VsanDisk and Start-SpbmReplicationTestFailover

There is nothing new on the install / update routines for Windows, so if you need guidance you can take a look at one of my previous article: VMware PowerCLI 10.1.0.

Read More
How to Upgrade ESXi from 6.5 to 6.7 with Command Line

How to Upgrade ESXi from 6.5 to 6.7 with Command Line

In a previous post I wrote about how to update ESXi 6.5 using Command Line. It’s 6.7 time now, so here is the article explaining how to upgrade ESXi from 6.5 to 6.7 with the command line (esxcli). This method works either the ESXi server is standalone or added to a vCenter Server (I will use no component of vCenter Server).

As a prerequisite, I placed the ESXi 6.5 server in maintenance mode.

Upgrade ESXi from 6.5 to 6.7 with Command Line - Maintenance Mode

Upgrade ESXi from 6.5 to 6.7 with Command Line – Check ESXi Version

To find the current version of ESXi, after I connected with PuTTY to the server, I ran this command:

esxcli system version get

Upgrade ESXi from 6.5 to 6.7 with Command Line - Check ESXi Version
Read More
Install VCSA 6.7

How to Install VCSA 6.7 (VMware vCenter Server Appliance)

In this article I will show you how to install VCSA 6.7 (VMware vCenter Server Appliance).

To start, you need an installation kit of vCenter Server Appliance 6.7. For this article, I will use the VCSA 6.7 Update 1 version – VMware-VCSA-all-6.7.0-10244745.iso (the latest available at the time I wrote this article).

Note: If you look for VCSA upgrade instructions, check this article: How to Upgrade vCenter Server Appliance from 6.5 to 6.7 – Stage 1.

Install VCSA 6.7 (VMware vCenter Server Appliance) – Stage 1

To launch the installer I will use a Windows virtual machine (alternatively you can use a Mac or a Linux system). Unzip the archive and navigate to VMware-VCSA-all-6.7.0-10244745\vcsa-ui-installer\win32 folder. Launch installer.exe and begin to install VCSA 6.7.

Install VCSA 6.7 - installer.exe

Read More

VMUG Romania October Meeting Report

Better late than never, so here it is the report for VMUG Romania latest meeting. On 16th October, 35 guests attended the last VMUG Romania meeting of the year. We held our meeting in the beautiful offices of our sponsor, Veeam. This meeting we added a new feature to our meeting: at the request of few remote colleagues, we streamed live on Facebook almost all the presentations. This allowed me to embed the videos into this article, so double win! We received cool feedback, so for next sessions we will have some sort of live streaming for sure.

I had the honor to present in the first slot of the meeting. As this year is the first year when Romania has not only one, but 2 vExperts, I thought this is a good opportunity to spread the word about vExpert program into the community. I talked about vExpert program, about the benefits of joining it and I showed the audience my path to vExpert. You can watch below my presentation in Romanian.

Read More

VCP6.5-DCV Delta Exam

VCP6.5-DCV Delta Exam Experience

Not so long ago I started to receive reminders from VMware Training Services about the expiration of my VCP6-DCV certification. With so many changes around, I patiently waited for the last reminder, one month to go. Read on for my journey with  VCP6.5-DCV Delta exam.

You generally have 3 ways to renew your certification:

  • Upgrade to VCAP
  • Update with the latest VCP exam (VCP6.5-DCV in my case)
  • Certify in a different technology track (for example VCP7-CMA)

Read More

VMSA-2018-0024

VMSA-2018-0024 – AirWatch Console Vulnerability

VMware has released a new security advisory VMSA-2018-0024: VMware Workspace ONE Unified Endpoint Management Console (AirWatch Console) update resolves SAML authentication bypass vulnerability.

This advisory documents the remediation of one critical issue: VMware Workspace ONE Unified Endpoint Management Console (AirWatch Console) contains a SAML authentication bypass vulnerability which can be leveraged during device enrollment. This vulnerability may allow for a malicious actor to impersonate an authorized SAML session if certificate-based authentication is enabled. If certificate-based authentication is not enabled the outcome of exploitation is limited to an information disclosure (Important Severity).

The Common Vulnerabilities and Exposures project has assigned the identifier CVE-2018-6979 to VMSA-2018-0019 issue.

VMSA-2018-0024 – Affected Products and Resolutions

AirWatch Console 9.7.x – update to version 9.7.0.3 or above
AirWatch Console 9.6.x – update to version 9.6.0.7 or above
AirWatch Console 9.5.x – update to version 9.5.0.16 or above
AirWatch Console 9.4.x – update to version 9.4.0.22 or above
AirWatch Console 9.3.x – update to version 9.3.0.25 or above
AirWatch Console 9.2.x – update to version 9.2.3.27 or above
AirWatch Console 9.1.x – update to version 9.1.5.6 or above

As per VMware KB, if patching your environment is not feasible in a timely manner, you can take mitigation steps by disabling SAML authentication for enrollment located under System > Enterprise Integration > Directory Services.

You can check reports on other VMware vulnerabilities in my page dedicated to Security Advisories.

VMUG Romania

VMUG Romania October Meeting

At VMUG Romania we have a busy October: on 2nd October we take part to VMware vForum Romania with a presentation booth, then on 16th October we will host our autumn meeting in a new venue, AFI Park 5, Bucharest.

If you don’t know what you can expect from such a meeting, you can read my report for the February VMUG meeting.

Agenda

Cornel Popescu  (Veeam) – Improve data protection with Veeam CDP for vSphere and Availability Orchestrator
Community session – Victor Homocea – vSAN in real life
Community session – Constatin Ghioc – All about vExpert
Community session – Razvan Ionescu – PowerCLI and bulding custom vSphere images
Cristian Radu (VMware) – VMware, what’s new

In the end we will host a raffle, be sure to be there to claim your prize 🙂

Location

AFI Park 5, 9th Floor
Veeam Software, Timisoara Avenue 4A
Bucharest, Romania, 061344

Participation is free. Registration is mandatory.

VMUG Romania meeting from 16 October 2018 is sponsored by Veeam.