Warning: VMware vCenter and Kemp LoadMaster Flaws Under Active Exploitation

Teilen:

Now-patched security flaws impacting Progress Kemp LoadMaster and VMware vCenter Server have come under active exploitation in the wild, it has emerged.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added CVE-2024-1212 (CVSS score: 10.0), a maximum-severity security vulnerability in Progress Kemp LoadMaster to its Known Exploited Vulnerabilities (KEV) catalog. It was addressed by Progress Software back in February 2024.

“Progress Kemp LoadMaster contains an OS command injection vulnerability that allows an unauthenticated, remote attacker to access the system through the LoadMaster management interface, enabling arbitrary system command execution,” the agency said.

Rhino Security Labs, which discovered and reported the flaw, said successful exploitation enables command execution on LoadMaster should an attacker have access to the administrator web user interface, granting them full access to the load balancer.

CISA’s addition of CVE-2024-1212 coincides with a warning from Broadcom that attackers are now exploiting two security flaws in the VMware vCenter Server, which were demonstrated at the Matrix Cup cybersecurity competition held in China earlier this year.

The flaws, CVE-2024-38812 (CVSS score: 9.8) and CVE-2024-38813 (CVSS score: 7.5), were originally resolved in September 2024, although the company rolled out fixes for the former a second-time last month, stating the previous patches “did not fully address” the problem.

  • CVE-2024-38812 – A heap-overflow vulnerability in the implementation of the DCERPC protocol that could permit a malicious actor with network access to obtain remote code execution
  • CVE-2024-38813 – A privilege escalation vulnerability that could permit a malicious actor with network access to escalate privileges to root

While there are currently no details on the observed exploitation of these vulnerabilities in real-world attacks, CISA is recommending that Federal Civilian Executive Branch (FCEB) agencies remediate CVE-2024-1212 by December 9, 2024, to secure their networks.

The development comes days after Sophos revealed that cybercrime actors are actively weaponizing a critical flaw in Veeam Backup & Replication (CVE-2024-40711, CVSS score: 9.8) to deploy a previously undocumented ransomware called Frag.

Ravie Lakshmanan

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
2:38 pm, Juni 1, 2025
Wetter-Symbol 21°C
L: 20° | H: 22°
aufgelockerte Bewölkung
Luftfeuchtigkeit: 43 %
Druck: 1013 mb
Wind: 14 mph WSW
Windböe: 0 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 45%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 4:49 am
Sonnenuntergang: 9:07 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Today 10:00 pm
Wetter-Symbol
20° | 22°°C 0 mm 0% 15 mph 62 % 1014 mb 0 mm/h
Tomorrow 10:00 pm
Wetter-Symbol
11° | 21°°C 0 mm 0% 11 mph 84 % 1019 mb 0 mm/h
Di. Juni 03 10:00 pm
Wetter-Symbol
11° | 19°°C 1 mm 100% 16 mph 93 % 1014 mb 0 mm/h
Mi. Juni 04 10:00 pm
Wetter-Symbol
10° | 20°°C 0 mm 0% 13 mph 80 % 1010 mb 0 mm/h
Do. Juni 05 10:00 pm
Wetter-Symbol
12° | 18°°C 1 mm 100% 13 mph 97 % 1008 mb 0 mm/h
Today 4:00 pm
Wetter-Symbol
17° | 21°°C 0 mm 0% 15 mph 43 % 1013 mb 0 mm/h
Today 7:00 pm
Wetter-Symbol
16° | 19°°C 0 mm 0% 12 mph 46 % 1013 mb 0 mm/h
Today 10:00 pm
Wetter-Symbol
15° | 17°°C 0 mm 0% 8 mph 62 % 1014 mb 0 mm/h
Tomorrow 1:00 am
Wetter-Symbol
13° | 13°°C 0 mm 0% 6 mph 84 % 1015 mb 0 mm/h
Tomorrow 4:00 am
Wetter-Symbol
11° | 11°°C 0 mm 0% 5 mph 79 % 1016 mb 0 mm/h
Tomorrow 7:00 am
Wetter-Symbol
11° | 11°°C 0 mm 0% 9 mph 72 % 1018 mb 0 mm/h
Tomorrow 10:00 am
Wetter-Symbol
16° | 16°°C 0 mm 0% 7 mph 51 % 1019 mb 0 mm/h
Tomorrow 1:00 pm
Wetter-Symbol
19° | 19°°C 0 mm 0% 8 mph 35 % 1018 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€91,856.05
0.06%
Ethereum(ETH)
€2,196.76
-1.72%
Fesseln(USDT)
€0.88
0.00%
XRP(XRP)
€1.89
-1.00%
Solana(SOL)
€133.90
-2.20%
USDC(USDC)
€0.88
0.00%
Dogecoin(DOGE)
€0.166754
-1.76%
Shiba Inu(SHIB)
€0.000011
1.38%
Pepe(PEPE)
€0.000010
-0.69%
Peanut das Eichhörnchen(PNUT)
€0.228360
2.34%
Nach oben scrollen