HomeSecurityVMware: Serious vulnerabilities in vCenter - Update immediately!

VMware: Serious vulnerabilities in vCenter - Update immediately!

VMware vCenter users vCenter versions 6.5, 6.7, and 7.0 as soon as possible, as there are serious vulnerabilities.

The most serious is CVE-2021-21985, which allows remote code execution and is located in a vSAN plugin, which is enabled by default in vCenter. An attacker can exploit this vulnerability and execute anything they want on the underlying machine, provided that port 443 is accessible.

See also: VMware: Fixes vulnerability that allows theft of administrator credentials

VMware

Even if users are not using vSAN, they are likely to be affected because the vSAN plugin is enabled by default.

“The vSphere Client (HTML5) contains a remote code execution vulnerability due to a lack of input validation in the Virtual SAN Health Check plug-in, which is enabled by default in vCenter Server,” VMware said.

VMware warned that attackers only need to "hit" port 443 to carry out the attack, so firewalls are the last line of defense for users.

“Organizations that have placed vCenter Servers on networks that are directly accessible from the Internet may not have this line of defense and should monitor their systems for breaches,” the company states.

“They should also take steps to implement more security controls (firewalls, ACLs, etc.) on the management interfaces of their infrastructure“.

To fix the issue, VMware recommends that users update vCenter. If they are unable to do so, they can follow the instructions the company has provided on how to disable vCenter Server plugins.

See also: Samsung: May update protects phones from Qualcomm vulnerability

“While vSAN will continue to function, management and monitoring capabilities are not possible while the plugin is disabled. A customer using vSAN should consider disabling the plugin only for short periods of time,” VMware warned.

See also: SQL Injection vulnerability in Anti-spam WordPress plugin exposes user data

"It needs your immediate attention if you are using vCenter Server," VMware said.

“In the age of ransomware, it's safer to assume that an attacker is already inside the network, so we strongly recommend that you patch as soon as possible“.

vCenter

Even having controls may not be enough, and VMware suggested users implement network segmentation.

“gangs Ransomware have repeatedly proven to the world that they are capable of compromising corporate networks by being patient, waiting for a new vulnerability to exploit,” he said.

The second vulnerability, CVE-2021-21986, could allow an attacker to perform actions allowed by plugins without authentication.

In terms of CVSSv3 scores, the CVE-2021-21985 vulnerability scored 9.8, while CVE-2021-21986 scored 6.5.

Earlier this year, two VMWare ESXi vulnerabilities were used by ransomware gangs to compromise virtual machines and encrypt virtual hard drives.

Source: ZDNet

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS