VMware Cloud on AWS (Including MSPs)
Infrastructure security impact statement:
-
VMware Cloud on AWS has completed the mitigation process for
CVE-2018-3646.
-
Based on current evaluations,
CVE-2018-3620 does not affect the
VMware Cloud on AWS infrastructure itself.
Recommended customer actions:
- No customer action required.
- 3rd party operating systems and VMware appliances deployed in an Organization’s SDDC may be affected by CVE-2018-3620. For information on VMware appliances please see KB55807. Customers are advised to contact their 3rd party operating system vendor to determine appropriate actions for mitigation of CVE-2018-3620.
Operational impact statement
VMware Workspace One SaaS (formerly Airwatch Saas)
Infrastructure security impact statement:
- Based on current evaluations, VMware Workspace One SaaS infrastructure is not impacted by CVE-2018-3646.
- Based on current evaluations, the VMware Workspace One SaaS infrastructure is not impacted by CVE-2018-3620.
Recommended customer actions:
- No customer action required.
- No customer action required.
Operational impact statement
- Customers should not experience any unscheduled operational impacts.
VMware Horizon Cloud
Infrastructure security impact statement:
- VMware Horizon Cloud is affected by CVE-2018-3646 but due to environmental factors the severity of the issue is lowered to Moderate from Important. The VMware Horizon Cloud infrastructure is architected to segment customer environments from one another, therefore, inter-organizational leaks between virtual machines are not possible as different organizations do not share ESXi hosts. Updates to are being prioritized to resolve CVE-2018-3646.
- Based on current evaluations, the VMware Horizon Cloud infrastructure is not impacted by CVE-2018-3620.
Recommended customer actions:
- No customer action required.
- Virtual Desktops may be affected by CVE-2018-3620. Customers are advised to contact their 3rd party operating system vendor to determine appropriate actions for mitigation of CVE-2018-3620.
Operational impact statement
- After maintenance is performed by VMware, which should by itself have no operational impact to their Organization's SDDC, customers will no longer be able to publish images until they have upgraded VMware Tools in their images to version 10.2.5 or above. Customers will not experience any impact with use of already provisioned VMs and published images. VMware will notify customers once updates are complete so that you may perform upgrades of VMTools in your images.