Broadcom VMware vCenter Server to address serious vulnerabilities that could allow hackers to execute remote code and escalate privileges.

The issues have been identified as CVE-2024-38812 and CVE-2024-38813, affecting multiple versions of vCenter Server and VMware Cloud Foundation.
Read more: AI tool lets you discover Zero-Day vulnerabilities
The most severe vulnerability, CVE-2024-38812, is related to a heap overflow in the DCERPC protocol and has a CVSS score of 9.8. This vulnerability could allow an attacker with network access to send specially crafted packets and execute remote code. The issue affects vCenter Server versions 7.0 and 8.0, as well as Cloud Foundation versions 4.x and 5.x.
Additionally, CVE-2024-38813, a privilege escalation vulnerability with a CVSS score of 7.5, allows hackers with network access to gain root-level privileges via malicious packets. Researchers Zbl and srs of the TZL team discovered these vulnerabilities during the Matrix Cup in China. While there are currently no known exploits, organizations are encouraged to apply the patches immediately.
See also: Zoom: New business capabilities to enhance security

For vCenter Server 8.0, users will need to upgrade to version 8.0 U3d, while version 7.0 customers will need to move to 7.0 U3t. Broadcom emphasizes the importance of patch updates for effective security and protection against attacks, as vCenter Server is a target for criminals and state-sponsored threat actors.
Read more: VMware fixes critical SQL Injection in HCX platform
Source: cybersecuritynews
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
