ZeroHour
The Hacker Newspublished ()ingested @TheHackersNews

VMware Issues Patches for Cloud Foundation, vCenter Server, and vSphere ESXi

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-34048
Unauthenticated Out-of-Bounds Write RCE in VMware vCenter Server

VMware vCenter Server contains an out-of-bounds write vulnerability (CWE-787) in its implementation of the DCERPC protocol. A remote, unauthenticated attacker with network access to vCenter Server can send crafted DCERPC traffic that corrupts memory, potentially leading to remote code execution on the vCenter appliance. Because vCenter is the central management plane for VMware vSphere environments, full compromise of it hands attackers a high-value foothold for lateral movement, consistent with the critical 9.8 CVSS score. Any organization running an affected VMware vCenter Server release is exposed (exact version ranges per VMware's advisory, including VMware Cloud Foundation deployments that bundle vCenter). Exploitation is confirmed in the wild: the flaw was added to CISA's KEV on 2024-01-22, a public PoC is available, news reports describe China-linked APT UNC3886 exploiting it as a zero-day, and EPSS estimates a 99.4% probability of exploitation within 30 days.

Do: Immediately upgrade vCenter Server — and VMware Cloud Foundation deployments that bundle it — to the patched builds identified in VMware's advisory, prioritizing internet-facing instances; if patching must wait, restrict network access to the vCenter management interface as the CISA KEV required action permits. Because exploitation is confirmed in the wild including by an APT, also hunt for signs of compromise such as unexpected processes or authentication activity on vCenter hosts and managed ESXi estate.

9.899% KEV PoC
  • VMware vCenter Server
mass≈100,000+ vCenter Server deployments globally (tens of thousands directly internet-exposed per public scans, far more reachable on internal networks)
CVE-2024-37079
Out-of-bounds Write in Broadcom VMware vCenter Server DCERPC Enables RCE

CVE-2024-37079 is an out-of-bounds write (CWE-787) in the implementation of the DCERPC protocol in VMware vCenter Server, Broadcom's management platform for vSphere virtualization environments. A malicious actor with network access to a vulnerable vCenter Server can trigger the flaw by sending specially crafted network packets, corrupting memory and potentially achieving remote code execution on the server. Successful exploitation would give an attacker control of a central management component, typically a strong foothold for lateral movement across the virtualized estate, though ransomware use is currently listed as unknown. Any organization running affected vCenter Server builds is exposed, with risk highest where the management interface is reachable from untrusted networks or the internet. CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2026-01-23, confirming exploitation in the wild; no public PoC is known, CVSS was not yet scored in the source data, and the high EPSS score (22.4%, 98th percentile) signals elevated near-term exploitation risk.

Do: Upgrade vCenter Server to a patched release per Broadcom's 2024 advisory (VMSA-2024-0012) without delay, since exploitation is confirmed in the wild and CISA BOD 22-01 requires federal agencies to apply vendor mitigations or discontinue use per the KEV deadline. Inventory your vCenter builds and compare them against the advisory's affected ranges; installations already patched for the 2024 DCERPC fixes are protected. Until patching completes, restrict network access to vCenter management interfaces (firewall allowlisting or VPN) and prioritize any internet-exposed instances.

9.822% KEV
  • Broadcom VMware vCenter Server
large≈tens of thousands of internet-exposed vCenter instances, with total deployments plausibly in the hundreds of thousands
CVE-2024-37080
+1 in the same advisory: …37081
vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol.

vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger this vulnerability by sending a specially crafted network packet potentially leading to remote code execution.

NVD description · AI analysis pending
9.8
group max
12%
  • vmware vcenter server
Full article276 words · extracted from thehackernews.com · click to collapse

Ravie LakshmananJun 18, 2024Network Security / Vulnerability

VMware has released updates to address critical flaws impacting Cloud Foundation, vCenter Server, and vSphere ESXi that could be exploited to achieve privilege escalation and remote code execution.

The list of vulnerabilities is as follows -

  • CVE-2024-37079 & CVE-2024-37080 (CVSS scores: 9.8) - Multiple heap-overflow vulnerabilities in the implementation of the DCE/RPC protocol that could allow a bad actor with network access to vCenter Server to achieve remote code execution by sending a specially crafted network packet
  • CVE-2024-37081 (CVSS score: 7.8) - Multiple local privilege escalation vulnerabilities in VMware vCenter arising due to the misconfiguration of sudo that an authenticated local user with non-administrative privileges could exploit to obtain root permissions

This is not the first time VMware has addressed shortcomings in the implementation of the DCE/RPC protocol. In October 2023, the Broadcom-owned virtualization services provider patched another critical security hole (CVE-2023-34048, CVSS score: 9.8) that could also be abused to execute arbitrary code remotely.

Chinese cybersecurity company QiAnXin LegendSec researchers Hao Zheng and Zibo Li have been credited with discovering and reporting CVE-2024-37079 and CVE-2024-37080. The discovery of CVE-2024-37081 has been credited to Matei "Mal" Badanoiu at Deloitte Romania.

All three issues, which affect vCenter Server versions 7.0 and 8.0, have been addressed in versions 7.0 U3r, 8.0 U1e, and 8.0 U2d.

While there are no known reports of any of the vulnerabilities being actively exploited in the wild, it's essential that users move quickly to apply the patches in light of their criticality.

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2024/06/vmware-issues-patches-for-cloud.html