Close Menu
Indo Guard OnlineIndo Guard Online
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
What's Hot

FBI warns about expanded spider attacks on airline using social engineering

June 28, 2025

The new AI Facebook tool asks for upload your photos for plot ideas, causing privacy trouble

June 28, 2025

From the theft of the browser to the intelligence collection instrument

June 28, 2025
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram YouTube
Indo Guard OnlineIndo Guard Online
Subscribe
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
Indo Guard OnlineIndo Guard Online
Home » Active exploitation of VMware vCenter and Kemp LoadMaster vulnerabilities
Global Security

Active exploitation of VMware vCenter and Kemp LoadMaster vulnerabilities

AdminBy AdminNovember 19, 2024No Comments2 Mins Read
Vulnerability
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link


November 19, 2024Ravi LakshmananVulnerability / Data Security

Vulnerability

Patched security flaws affecting Progress Kemp LoadMaster and VMware vCenter Server have been found to be actively exploited in the wild.

The US Cybersecurity and Infrastructure Security Agency (CISA) on Monday added CVE-2024-1212 (CVSS Score: 10.0), the highest level security vulnerability in Progress Kemp LoadMaster to known vulnerabilities that exploit (KEV) directory. It was addressed by Progress Software back to February 2024.

“Progress Kemp LoadMaster contains an OS command injection vulnerability that allows an unauthenticated remote attacker to gain access to the system via the LoadMaster management interface, allowing arbitrary system commands to be executed,” the agency said.

Cyber ​​security

Rhino Security Labs which revealed and reported a shortage said a successful exploit allows commands to be executed on the LoadMaster when the attacker has access to the web admin interface, giving them full access to the load balancer.

CISA’s addition of CVE-2024-1212 coincides with a a warning from Broadcom that attackers are now exploiting two security flaws in VMware’s vCenter server that were demonstrated at the Matrix Cup cybersecurity competition held in China earlier this year.

CVE-2024-38812 (CVSS score: 9.8) and CVE-2024-38813 (CVSS score: 7.5) were originally decided in September 2024, although the company patches deployed for the former for a second time last month, saying previous patches “didn’t fully resolve” the problem.

  • CVE-2024-38812 – A heap overflow vulnerability in the DCERPC protocol implementation that could allow a malicious actor with network access to obtain remote code execution
  • CVE-2024-38813 – An elevation of privilege vulnerability that could allow an attacker with network access to elevate the privileges of root
Cyber ​​security

Although there are currently no details on the observed exploitation of these vulnerabilities in actual attacks, CISA recommends that Federal Civil Executive Branch (FCEB) agencies patch CVE-2024-1212 by December 9, 2024 to protect their networks.

The development comes days after Sophos revealed that cybercriminals are actively exploiting a critical flaw in Veeam Backup & Replication (CVE-2024-40711CVSS score: 9.8) to deploy a previously undocumented ransomware called Frag.

Did you find this article interesting? Follow us Twitter  and LinkedIn to read more exclusive content we publish.





Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Admin
  • Website

Related Posts

FBI warns about expanded spider attacks on airline using social engineering

June 28, 2025

The new AI Facebook tool asks for upload your photos for plot ideas, causing privacy trouble

June 28, 2025

From the theft of the browser to the intelligence collection instrument

June 28, 2025

More than 1000 SOHO devices hacked in China associated with cyber-science associated with cyber

June 27, 2025

Posted and Pubshell Sarsware used in Tibet’s Mustang Panda attack

June 27, 2025

The Chinese Silver Fox Group uses fake web -sats to deliver Sainbox Rat and Hidden Rortkit

June 27, 2025
Add A Comment
Leave A Reply Cancel Reply

Loading poll ...
Coming Soon
Do You Like Our Website
: {{ tsp_total }}

Subscribe to Updates

Get the latest security news from Indoguardonline.com

Latest Posts

FBI warns about expanded spider attacks on airline using social engineering

June 28, 2025

The new AI Facebook tool asks for upload your photos for plot ideas, causing privacy trouble

June 28, 2025

From the theft of the browser to the intelligence collection instrument

June 28, 2025

More than 1000 SOHO devices hacked in China associated with cyber-science associated with cyber

June 27, 2025

Posted and Pubshell Sarsware used in Tibet’s Mustang Panda attack

June 27, 2025

The Chinese Silver Fox Group uses fake web -sats to deliver Sainbox Rat and Hidden Rortkit

June 27, 2025

Business -SUCKS FOR AGENTIC AI SOC -Analytics

June 27, 2025

Transfer of person transfer is increased by threats when directed by scanning and disadvantages CVE

June 27, 2025
About Us
About Us

Provide a constantly updating feed of the latest security news and developments specific to Indonesia.

Facebook X (Twitter) Pinterest YouTube WhatsApp
Our Picks

FBI warns about expanded spider attacks on airline using social engineering

June 28, 2025

The new AI Facebook tool asks for upload your photos for plot ideas, causing privacy trouble

June 28, 2025

From the theft of the browser to the intelligence collection instrument

June 28, 2025
Most Popular

In Indonesia, crippling immigration ransomware breach sparks privacy crisis

July 6, 2024

Why Indonesia’s Data Breach Crisis Calls for Better Security

July 6, 2024

Indonesia’s plan to integrate 27,000 govt apps in one platform welcomed but data security concerns linger

July 6, 2024
© 2025 indoguardonline.com
  • Home
  • About us
  • Contact us
  • Privacy Policy

Type above and press Enter to search. Press Esc to cancel.