Week in review: Critical VMware vCenter Server bugs fixed, Apple releases iOS 18
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2024-38112 | Windows MSHTML Platform Spoofing Vulnerability Exploited in the Wild (CVE-2024-38112) CVE-2024-38112 is a spoofing flaw (CWE-451) in the Microsoft Windows MSHTML platform, the Windows component used to render web content, including by applications that embed the legacy Internet Explorer engine. It is triggered when a user interacts with attacker-controlled content rendered through MSHTML: the attack requires no privileges, travels over the network, and needs user interaction (UI:R per its CVSS vector), letting an attacker misrepresent critical UI information to the victim. Despite being classified as spoofing, the CVSS impact scores are high across confidentiality, integrity, and availability, and the CVSS base score is 7.5 (High). Any system running the affected Windows 10 (1507, 1607, 1809, 21H2, 22H2), Windows 11 (21H2, 22H2, 23H2), or Windows Server (2008, 2012, 2016, 2019) releases is affected. Exploitation is confirmed in the wild: Microsoft patched it as an actively exploited zero-day in July 2024, CISA added it to the Known Exploited Vulnerabilities catalog on 2024-07-09, and reporting indicates it had been exploited for over a year before the fix. Do: Apply Microsoft's July 2024 security updates (Patch Tuesday) across all affected Windows 10, Windows 11, and Windows Server versions, prioritizing internet-facing and user workstations given confirmed in-the-wild exploitation and the 84.2% EPSS score. Until patched, remind users to avoid interacting with untrusted web or document content, since exploitation requires user interaction. Track the fix against CISA's KEV catalog deadlines and verify patch status on all endpoints. | 7.5 | 84% | KEV |
| masshundreds of millions of Windows devices (essentially all desktops and servers on the listed Windows 10/11 and Windows Server releases) | |
| CVE-2024-38812 +1 in the same advisory: …38813 | Unauthenticated RCE in VMware vCenter Server via DCERPC heap overflow VMware vCenter Server contains a heap-based buffer overflow (CWE-122/CWE-787) in its implementation of the DCERPC protocol. A remote attacker with network access to vCenter Server can trigger the flaw by sending a specially crafted network packet; no credentials, privileges, or user interaction are required (CVSS:3.1/AV:N/AC:L/PR:N/UI:N). Successful exploitation can lead to remote code execution with high impact on confidentiality, integrity, and availability of the vCenter host. Affected products are VMware vCenter Server and VMware Cloud Foundation deployments, with the exact vulnerable version ranges specified in the Broadcom/VMware advisory. The flaw is confirmed to be exploited in the wild: CISA added it to the KEV catalog on 2024-11-20, EPSS estimates a 54.6% probability of exploitation within 30 days (99th percentile), and related reporting describes PRC hackers using the BRICKSTORM backdoor in campaigns involving actively exploited VMware vCenter flaws; no public proof-of-concept is known. Do: Apply the patched vCenter Server / VMware Cloud Foundation releases issued by Broadcom per the vendor advisory, and because reporting indicates the fix was re-issued, verify the latest patched build is actually installed rather than an earlier, possibly incomplete one. Prioritize patching internet-facing vCenter instances and restrict network access to the vCenter management interface in the interim. Per the CISA KEV required action, apply vendor mitigations or discontinue use if mitigations are unavailable, and hunt for signs of post-exploitation (e.g., BRICKSTORM activity) given confirmed in-the-wild exploitation. | 9.8 | 55% | KEV |
| largeseveral thousand internet-exposed vCenter instances per public scans; on the order of 100,000+ total vCenter deployments worldwide (estimate) | |
| CVE-2024-43461 | Windows MSHTML Platform Spoofing Vulnerability Exploited as Zero-Day (CVE-2024-43461) CVE-2024-43461 is a spoofing vulnerability (CWE-451, user interface misrepresentation) in the Windows MSHTML platform that lets attacker-controlled content misrepresent critical UI information to users. The attack is network-delivered and succeeds when a victim interacts with crafted content — such as opening a malicious file or link rendered by MSHTML — so they believe they are handling something benign (public reporting ties the observed campaign to malicious shortcut files that appeared to be ordinary documents). Successful exploitation deceives the user and, given the high confidentiality, integrity, and availability ratings in the CVSS score, can support follow-on compromise, including delivery of attacker-supplied payloads by the Void Banshee APT. Anyone running the affected Windows releases — Windows 10 (1507, 1607, 1809, 21H2, 22H2), Windows 11 (21H2 through 24H2), and Windows Server 2008, 2012, and 2016 — is in scope. The flaw was exploited in the wild as a zero-day before it was patched in Microsoft's September 2024 updates, was added to CISA's Known Exploited Vulnerabilities catalog on 2024-09-16, and no public PoC is known. Do: Apply Microsoft's September 2024 cumulative Windows security updates to all Windows 10/11 and Windows Server 2008/2012/2016 systems, prioritizing user workstations since exploitation requires user interaction, per the CISA KEV required action. Hunt for Void Banshee APT lures — files or shortcuts whose displayed type does not match their true format — and verify patched build status across the estate, as an earlier related fix was reportedly lost to a code defect and reissued. | 8.8 | 54% | KEV |
| masshundreds of millions to 1+ billion Windows client and server installations (MSHTML is a core component of every listed Windows release) | |
| CVE-2024-45488 | One Identity Safeguard for Privileged Passwords before 7.5.2 allows unauthorized access because of an issue related to cookies. One Identity Safeguard for Privileged Passwords before 7.5.2 allows unauthorized access because of an issue related to cookies. This only affects virtual appliance installations (VMware or HyperV). The fixed versions are 7.0.5.1 LTS, 7.4.2, and 7.5.2. NVD description · AI analysis pending | 9.8 | 51% | — | — | ||
| CVE-2024-8190 | OS Command Injection RCE in Ivanti Cloud Services Appliance 4.6 Ivanti Cloud Services Appliance versions 4.6 Patch 518 and before contain an OS command injection flaw (CWE-78) that allows a remote, authenticated attacker to achieve remote code execution. The attacker must already hold administrator-level privileges on the appliance, and exploitation is triggered by sending crafted input to the appliance over the network. Successful exploitation yields arbitrary command execution on the CSA, and related reporting indicates nation-state actors have been exploiting Ivanti CSA flaws for network infiltration, including attacks on French government and telecom targets. Only organizations still running CSA 4.6.x are affected, and that product line has reached end-of-life and will not receive further security updates. The vulnerability was added to CISA's Known Exploited Vulnerabilities catalog on 2024-09-13 and carries a very high EPSS score (88.5%, 100th percentile), signaling confirmed and likely ongoing exploitation in the wild. Do: Because CSA 4.6.x has reached end-of-life, remove CSA 4.6.x from service or migrate to the supported 5.0.x line, as future 4.6.x flaws are unlikely to receive fixes. Given confirmed nation-state exploitation, hunt for signs of compromise such as unexpected admin sessions, processes, or network tunnels, and restrict internet exposure of any remaining 4.6.x appliances in the interim. | 7.2 | 89% | KEV |
| moderateroughly 1,000–2,000 internet-exposed CSA appliances (public internet scan counts) |
Full article1,109 words · extracted from helpnetsecurity.com · click to collapse

Here’s an overview of some of last week’s most interesting news, articles, interviews and videos:
Critical VMware vCenter Server bugs fixed (CVE-2024-38812)
Broadcom has released fixes for two vulnerabilities affecting VMware vCenter Server that can be triggered by sending a specially crafted network packet, and could lead to remote code execution (CVE-2024-38812) or privilege escalation (CVE-2024-38813).
Apple releases iOS 18, with security and privacy improvements
Apple has launched iOS 18, the latest significant iteration of the operating system powering its iPhones. Along with many new features and welcome customization options, iOS 18 brings several changes for improving users’ security and privacy.
Striking the balance between cybersecurity and operational efficiency
In this Help, Net Security interview, Michael Oberlaender, ex-CISO, and book author, discusses how to strike the right balance between security and operational efficiency.
Essential metrics for effective security program assessment
In this Help Net Security interview, Alex Spivakovsky, VP of Research & Cybersecurity at Pentera, discusses essential metrics for evaluating the success of security programs.
CrowdSec: Open-source security solution offering crowdsourced protection
Crowdsec is an open-source solution that offers crowdsourced protection against malicious IPs.
Detecting vulnerable code in software dependencies is more complex than it seems
In this Help Net Security interview, Henrik Plate, CISSP, security researcher, Endor Labs, discusses the complexities AppSec teams face in identifying vulnerabilities within software dependencies.
The proliferation of non-human identities
97% of non-human identities (NHIs) have excessive privileges, increasing unauthorized access and broadening the attack surface, according to Entro Security’s 2025 State of Non-Human Identities and Secrets in Cybersecurity report.
The growing danger of visual hacking and how to protect against it
In this Help Net Security interview, Robert Ramsey, CEO at Rain Technology, discusses the growing threat of visual hacking, how it bypasses traditional cybersecurity measures, and the importance of physical barriers like switchable privacy screens.
EchoStrike: Generate undetectable reverse shells, perform process injection
EchoStrike is an open-source tool designed to generate undetectable reverse shells and execute process injection on Windows systems.
Compliance frameworks and GenAI: The Wild West of security standards
In this Help Net Security interview, Kristian Kamber, CEO at SplxAI, discusses how security challenges for GenAI differ from traditional software. Unlike predictable software, GenAI introduces dynamic, evolving threats, requiring new strategies for defense and compliance.
Windows users targeted with fake human verification pages delivering malware
For a while now, security researchers have been warning about fake human verification pages tricking Windows users into inadvertently installing malware.
Patch this critical Safeguard for Privileged Passwords auth bypass flaw (CVE-2024-45488)
Researchers have released technical details about CVE-2024-45488, a critical authentication bypass vulnerability affecting One Identity’s Safeguard for Privileged Passwords (SPP), which could allow attackers to gain full administrative access to the virtual appliance.
FBI forced Flax Typhoon to abandon its botnet
A botnet operated by the Chinese state-sponsored threat actor known as Flax Typhoon has been disrupted by the law enforcement agency and abandoned by the group, FBI Director Chris Wray confirmed on Wednesday.
Hackers breaching construction firms via specialized accounting software
Firms in the construction industry are getting breached by hackers via internet-exposed servers running Foundation accounting software, Huntress researchers are warning.
Ghost: Criminal communication platform compromised, dismantled by international law enforcement
Another encrypted communication platform used by criminals has been dismantled and its alleged mastermind arrested, the Australian Federal Police has announced on Tuesday.
PoC exploit for exploited Ivanti Cloud Services Appliance flaw released (CVE-2024-8190)
CVE-2024-8190, an OS command injection vulnerability in Ivanti Cloud Services Appliance (CSA) v4.6, is under active exploitation.
Microsoft confirms second 0-day exploited by Void Banshee APT (CVE-2024-43461)
CVE-2024-43461, a spoofing vulnerability affecting Windows MSHTML – a software component used by various apps for rendering web pages on Windows – “was exploited as a part of an attack chain relating to CVE-2024-38112, prior to July 2024,” Microsoft has revealed.
How to detect and stop bot activity
Bad bot traffic continues to rise year-over-year, accounting for nearly a third of all internet traffic in 2023.
How digital wallets work, and best practices to use them safely
In this Help Net Security video, Kayne McGladrey, IEEE Senior Member, discusses best practices for using digital wallets safely.
Trends and dangers in open-source software dependencies
A C-suite perspective on potential vulnerabilities within open-source dependencies or software packages reveals that, while remediation costs for dependency risks are perilously high, function-level reachability analysis still offers the best value in this critical area, according to Endor Labs.
Differential privacy in AI: A solution creating more problems for developers?
In the push for secure AI models, many organizations have turned to differential privacy. But is the very tool meant to protect user data holding back innovation?
The ripple effects of regulatory actions on CISO reporting
In this Help Net Security video, Sara Behar, Content Manager at YL Ventures, discusses how recent regulatory actions and high-profile legal incidents involving cybersecurity leaders have influenced CISO reporting.
The cybersecurity workforce of the future requires diverse hiring practices
The global cybersecurity workforce gap reached a new high with an estimated 4.8 million professionals needed to effectively secure organizations, a 19% year-on-year increase, according to ISC2.
Data disposal and cyber hygiene: Building a culture of security within your organization
To build a defense against data breaches, organizations must go beyond the traditional methods of cyber hygiene and expand their domain to include policies governing data protection from creation to disposal of IT assets, safeguarding sensitive, confidential data at all stages.
Organizations overwhelmed by numerous and insecure remote access tools
Organizations are combating excessive remote access demands with an equally excessive number of tools that provide varying degrees of security, according to Claroty.
Gateways to havoc: Overprivileged dormant service accounts
Service accounts are often overprivileged, forgotten about and lack proper password security protocols. Some of these once-productive service accounts become dormant over time, making them suitable targets for threat actors.
Beyond human IAM: The rising tide of machine identities
Remember when managing user accounts was your biggest headache? Those were simpler times. Today, we’re drowning in a sea of machine identities, and it’s time to learn how to swim – or risk going under.
Cybersecurity jobs available right now: September 18, 2024
We’ve scoured the market to bring you a selection of roles that span various skill levels within the cybersecurity field. Check out this weekly selection of cybersecurity jobs available right now.
Rising identity security risks: Why organizations must act now
As the priority for managing digital identities intensifies, organizations are encountering severe identity security risks.
New infosec products of the week: September 20, 2024
Here’s a look at the most interesting products from the past week, featuring releases from anecdotes, F5 Networks, Gcore, Rapid7, Strivacity, and Veritas Technologies.
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2024/09/22/week-in-review-critical-vmware-vcenter-server-bugs-fixed-apple-releases-ios-18/