Broadcom fixes critical RCE bug in VMware vCenter Server

Teilen:

Broadcom has fixed a critical VMware vCenter Server vulnerability that attackers can exploit to gain remote code execution on unpatched servers via a network packet.

vCenter Server is the central management hub for VMware’s vSphere suite, helping administrators manage and monitor virtualized infrastructure.

The vulnerability (CVE-2024-38812), reported by TZL security researchers during China’s 2024 Matrix Cup hacking contest, is caused by a heap overflow weakness in vCenter’s DCE/RPC protocol implementation. It also affects products containing vCenter, including VMware vSphere and VMware Cloud Foundation.

Unauthenticated attackers can exploit it remotely in low-complexity attacks that don’t require user interaction “by sending a specially crafted network packet potentially leading to remote code execution.”

Security patches addressing this vulnerability are now accessible through the standard vCenter Server update mechanisms.

“To ensure full protection for yourself and your organization, install one of the update versions listed in the VMware Security Advisory,” the company said.

“While other mitigations may be available depending on your organization’s security posture, defense-in-depth strategies, and firewall configurations, each organization must evaluate the adequacy of these protections independently.”

Not exploited in attacks

Broadcom says it has not found evidence that the CVE-2024-38812 RCE bug is currently exploited in attacks.

Admins who are unable to immediately apply today’s security updates should strictly control network perimeter access to vSphere management components and interfaces, including storage and network components, as an official workaround for this vulnerability is unavailable.

Today, the company also patched a high-severity privilege escalation vulnerability (CVE-2024-38813) that threat actors can leverage to gain root privileges on vulnerable servers via a specially crafted network packet.

In June, it fixed a similar vCenter Server remote code execution vulnerability (CVE-2024-37079) that can be exploited via specially crafted packets.

In January, Broadcom disclosed that a Chinese hacking group has been exploiting a critical vCenter Server vulnerability (CVE-2023-34048) as a zero-day since at least late 2021.

The threat group (tracked as UNC3886 by security firm Mandiant) used it to breach vulnerable vCenter servers to deploy VirtualPita and VirtualPie backdoors on ESXi hosts via maliciously crafted vSphere Installation Bundles (VIBs).

Sergiu Gatlan

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
5:52 am, Jan. 26, 2025
Wetter-Symbol 3°C
L: 2° | H: 4°
klarer Himmel
Luftfeuchtigkeit: 81 %
Druck: 1004 mb
Wind: 7 mph SE
Windböe: 0 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 6%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 7:47 am
Sonnenuntergang: 4:38 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Today 9:00 pm
Wetter-Symbol
2° | 4°°C 1 mm 100% 20 mph 90 % 1004 mb 0 mm/h
Tomorrow 9:00 pm
Wetter-Symbol
6° | 8°°C 1 mm 100% 26 mph 90 % 981 mb 0 mm/h
Di. Jan. 28 9:00 pm
Wetter-Symbol
6° | 9°°C 1 mm 100% 23 mph 85 % 1002 mb 0 mm/h
Mi. Jan. 29 9:00 pm
Wetter-Symbol
4° | 8°°C 1 mm 100% 12 mph 96 % 1005 mb 0 mm/h
Do. Jan. 30 9:00 pm
Wetter-Symbol
3° | 7°°C 1 mm 100% 13 mph 95 % 1020 mb 0 mm/h
Today 6:00 am
Wetter-Symbol
3° | 4°°C 0 mm 0% 9 mph 81 % 1004 mb 0 mm/h
Today 9:00 am
Wetter-Symbol
4° | 5°°C 0 mm 0% 14 mph 82 % 1003 mb 0 mm/h
Today 12:00 pm
Wetter-Symbol
5° | 6°°C 0.23 mm 23% 18 mph 81 % 999 mb 0 mm/h
Today 3:00 pm
Wetter-Symbol
6° | 6°°C 1 mm 100% 20 mph 90 % 989 mb 0 mm/h
Today 6:00 pm
Wetter-Symbol
8° | 8°°C 1 mm 100% 14 mph 82 % 988 mb 0 mm/h
Today 9:00 pm
Wetter-Symbol
9° | 9°°C 0 mm 0% 15 mph 80 % 986 mb 0 mm/h
Tomorrow 12:00 am
Wetter-Symbol
8° | 8°°C 1 mm 100% 19 mph 90 % 978 mb 0 mm/h
Tomorrow 3:00 am
Wetter-Symbol
7° | 7°°C 1 mm 100% 14 mph 77 % 980 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€100,135.18
0.78%
Ethereum(ETH)
€3,185.95
1.51%
XRP(XRP)
€2.98
0.82%
Fesseln(USDT)
€0.95
-0.01%
Solana(SOL)
€245.99
3.61%
Dogecoin(DOGE)
€0.337870
1.39%
USDC(USDC)
€0.95
-0.01%
Shiba Inu(SHIB)
€0.000019
0.34%
Pepe(PEPE)
€0.000014
0.21%
Peanut das Eichhörnchen(PNUT)
€0.341643
3.03%
Nach oben scrollen