
VMware has patched a critical vulnerabilitythat could have allowed attackers to access sensitive information.
The vulnerability, which is known as CVE-2020-3952, has been rated as critical and has a CVSSv3 score of 10.
Vulnerability in VMware vCenter Server
In some cases, vmdir does not properly implement security controls , which allows attackers to gain network access and also access sensitive information .
By gaining access to this information, a malicious actor can hack the vCenter server or other services that depend on vmdir for authentication.
If you are using vCenter Server version 6.7, it is recommended that you install the 6.7u3f update to fix this critical vulnerability.
As VMware stated, “clean installations of vCenter Server 6.7 (embedded or external PSC) are not affected by this vulnerability.”
In March, VMware addressed attacks in Workstation, Fusion, VMware Remote Console, and Horizon Client. The company also published KB 78543 for more details, in case vCenter Server 6.7 deployments are affected.
VMware vCenter Server is a centralized management platform for VMware virtualized environments. It provides powerful capabilities for managing virtual machines (VMs) and physical resources, allowing administrators to control and monitor their infrastructure from a single point. With VMware vCenter Server, organizations can automate many processes, optimize performance, and ensure the security of their virtual environments, while supporting the development and maintenance of their infrastructure.
