Close Menu
Indo Guard OnlineIndo Guard Online
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
What's Hot

Invitation to Disagreement Link from ASYNCRAT and SKULD Theft, focused on cry

June 14, 2025

More than 269 000 sites infected with malicious JSFiretruC JavaScript software in one month

June 13, 2025

Transition from Monitoring Alert to Risk Measurement

June 13, 2025
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram YouTube
Indo Guard OnlineIndo Guard Online
Subscribe
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
Indo Guard OnlineIndo Guard Online
Home » A patch is issued for a critical vulnerability in VMware vCenter that allows remote code execution
Global Security

A patch is issued for a critical vulnerability in VMware vCenter that allows remote code execution

AdminBy AdminSeptember 18, 2024No Comments2 Mins Read
VMware vCenter
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link


September 18, 2024Ravi LakshmananVirtualization / Network Security

VMware vCenter

Broadcom on Tuesday released updates to address a critical security flaw affecting VMware vCenter Server that could open the way for remote code execution.

The vulnerability tracked as CVE-2024-38812 (CVSS score: 9.8) was described as a heap overflow vulnerability in DCE/RPC protocol.

“An attacker with network access to vCenter Server could cause this vulnerability by sending a specially crafted network packet that could potentially lead to remote code execution,” the virtualization service provider. said in the bulletin.

Cyber ​​security

The flaw is similar to two other remote code execution flaws, CVE-2024-37079 and CVE-2024-37080 (CVSS scores: 9.8) that VMware decided on vCenter Server in June 2024.

VMware also addressed an elevation of privilege flaw in vCenter Server (CVE-2024-38813, CVSS Score: 7.5), which could allow a malicious actor with network access to an instance to elevate privileges to root by sending a specially crafted network packet.

Security researchers zbl and srs from the TZL team are credited with discovering and reporting the two flaws during The Matrix Cup cyber security competition held in China in June 2024. These have been fixed in the following versions –

  • vCenter Server 8.0 (fixed in 8.0 U3b)
  • vCenter Server 7.0 (fixed in 7.0 U3s)
  • VMware Cloud Foundation 5.x (fixed in 8.0 U3b as an asynchronous patch)
  • VMware Cloud Foundation 4.x (fixed in 7.0 U3s as an asynchronous patch)

Broadcom said it was not aware of any malicious use of the two vulnerabilities, but urged customers to update their installations to the latest versions to guard against potential threats.

“These vulnerabilities are memory management and corruption issues that could be exploited against VMware vCenter services, potentially allowing remote code execution,” the company said in a statement. said.

Cyber ​​security

The event comes after the US Cybersecurity and Infrastructure Security Agency (CISA) and the Federal Bureau of Investigation (FBI) released joint advisory urging organizations to work to address cross-site scripting (XSS) vulnerabilities that threat actors can use to compromise systems.

“Cross-site scripting vulnerabilities occur when manufacturers fail to properly handle, sanitize, or avoid introductions,” state authorities note. said. “These flaws allow threat actors to inject malicious scripts into web applications, using them to manipulate, steal, or misuse data in a variety of contexts.”

Did you find this article interesting? Follow us Twitter  and LinkedIn to read more exclusive content we publish.





Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Admin
  • Website

Related Posts

Invitation to Disagreement Link from ASYNCRAT and SKULD Theft, focused on cry

June 14, 2025

More than 269 000 sites infected with malicious JSFiretruC JavaScript software in one month

June 13, 2025

Transition from Monitoring Alert to Risk Measurement

June 13, 2025

Band

June 13, 2025

Apple Zero Click’s downside in reports to spy on journalists using spyware Paragon software

June 13, 2025

Both Vextrio and affiliates control the global network

June 12, 2025
Add A Comment
Leave A Reply Cancel Reply

Loading poll ...
Coming Soon
Do You Like Our Website
: {{ tsp_total }}

Subscribe to Updates

Get the latest security news from Indoguardonline.com

Latest Posts

Invitation to Disagreement Link from ASYNCRAT and SKULD Theft, focused on cry

June 14, 2025

More than 269 000 sites infected with malicious JSFiretruC JavaScript software in one month

June 13, 2025

Transition from Monitoring Alert to Risk Measurement

June 13, 2025

Band

June 13, 2025

Apple Zero Click’s downside in reports to spy on journalists using spyware Paragon software

June 13, 2025

Both Vextrio and affiliates control the global network

June 12, 2025

How to Decide Safety Expanding

June 12, 2025

The new tokenbreak attack combines AI moderation with a one -sided character change

June 12, 2025
About Us
About Us

Provide a constantly updating feed of the latest security news and developments specific to Indonesia.

Facebook X (Twitter) Pinterest YouTube WhatsApp
Our Picks

Invitation to Disagreement Link from ASYNCRAT and SKULD Theft, focused on cry

June 14, 2025

More than 269 000 sites infected with malicious JSFiretruC JavaScript software in one month

June 13, 2025

Transition from Monitoring Alert to Risk Measurement

June 13, 2025
Most Popular

In Indonesia, crippling immigration ransomware breach sparks privacy crisis

July 6, 2024

Why Indonesia’s Data Breach Crisis Calls for Better Security

July 6, 2024

Indonesia’s plan to integrate 27,000 govt apps in one platform welcomed but data security concerns linger

July 6, 2024
© 2025 indoguardonline.com
  • Home
  • About us
  • Contact us
  • Privacy Policy

Type above and press Enter to search. Press Esc to cancel.