ZeroHour
The Recordpublished ()ingested

VMware warns of critical vulnerability affecting vCenter Server product

criticalVulnerabilityimportance 60CVE-2023-34048

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-34048
Unauthenticated Out-of-Bounds Write RCE in VMware vCenter Server

VMware vCenter Server contains an out-of-bounds write vulnerability (CWE-787) in its implementation of the DCERPC protocol. A remote, unauthenticated attacker with network access to vCenter Server can send crafted DCERPC traffic that corrupts memory, potentially leading to remote code execution on the vCenter appliance. Because vCenter is the central management plane for VMware vSphere environments, full compromise of it hands attackers a high-value foothold for lateral movement, consistent with the critical 9.8 CVSS score. Any organization running an affected VMware vCenter Server release is exposed (exact version ranges per VMware's advisory, including VMware Cloud Foundation deployments that bundle vCenter). Exploitation is confirmed in the wild: the flaw was added to CISA's KEV on 2024-01-22, a public PoC is available, news reports describe China-linked APT UNC3886 exploiting it as a zero-day, and EPSS estimates a 99.4% probability of exploitation within 30 days.

Do: Immediately upgrade vCenter Server — and VMware Cloud Foundation deployments that bundle it — to the patched builds identified in VMware's advisory, prioritizing internet-facing instances; if patching must wait, restrict network access to the vCenter management interface as the CISA KEV required action permits. Because exploitation is confirmed in the wild including by an APT, also hunt for signs of compromise such as unexpected processes or authentication activity on vCenter hosts and managed ESXi estate.

9.899% KEV PoC
  • VMware vCenter Server
mass≈100,000+ vCenter Server deployments globally (tens of thousands directly internet-exposed per public scans, far more reachable on internal networks)
Full article440 words · extracted from therecord.media · click to collapse

Cloud computing giant VMware warned this week of new vulnerabilities affecting a server management product present in VMware vSphere and Cloud Foundation (VCF) products.

The affected product, VMware vCenter Server, provides a centralized platform for controlling customers’ vSphere environments.

On Tuesday, the company released an advisory and FAQ document outlining concerns around CVE-2023-34048, a vulnerability with a critical CVSS severity score of 9.8 out of 10.

Discovered by Grigory Dorodnov of Trend Micro Zero Day Initiative, the bug allows a hacker to compromise vulnerable servers.

VMware noted that while it typically does not mention end-of-life products in most advisories, “due to the critical severity of this vulnerability and lack of workaround VMware has made a patch generally available for vCenter Server 6.7U3, 6.5U3, and VCF 3.x.”

VMware noted that because it affects the popular vCenter Server, “the scope is large” and customers should consider this an “emergency change” that necessitates “acting quickly.”

The company is not currently aware of exploitation “in the wild.”

Viakoo Labs Vice President John Gallagher said the vulnerability is “as serious as it gets” because vCenter Server is a widely-used centralized platform for managing multiple VMware instances, and is used by a wide range of organizations and engineering teams.

“Successful exploit of this CVE gives complete access to the environment, and enables remote code execution for further exploitation. A sign of how deeply serious this is can be seen in how VMware has published patches for older, end of support/end of life versions of the product,” Gallagher said.

“Given the breadth of usage and how even older versions are still being used, it’s likely that patching will take some time leaving open the ‘window of vulnerability’ for some time.”

Irfan Asrar, director of threat research at Qualys, backed Gallagher’s assessment, warning that the affected products are “highly prevalent applications with large enterprise customers globally.”

“Given the fact that it’s a remote code exploit with a high severity score, organizations should take this very seriously, especially with the current geopolitical climate,” Asrar added. “Other than the obvious use case as a vector for ransomware, this could also be used to send messages by threat actors on a hacktivist agenda.”

Ransomware gangs have a history of targeting VMWare vCenter servers with attacks, with several groups going after the products using Log4Shell attacks.

No previous article

No new articles

Jonathan Greig

is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.

Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/vmware-warns-vulnerability-vsphere-center