Enterprise IT Support β€’ Bangkok & Nationwide

Technology newsroom

🚨 Urgent Alert! Critical VMware vCenter Vulnerabilities Exploited to Embed Reverse SSH for Remote System Takeover

Hackers are exploiting Critical vulnerabilities in VMware vCenter Server (CVE-2024-37079, CVE-2024-37080) to install Reverse SSH tools for persistent remote access and system control. Administrators should update patches urgently.

Edited by SyncTech Solution Published Source Original source
🚨 Urgent Alert! Critical VMware vCenter Vulnerabilities Exploited to Embed Reverse SSH for Remote System Takeover

πŸ“Œ Key Takeaways:
- An active campaign is exploiting Critical vulnerabilities (CVE-2024-37079, CVE-2024-37080) in VMware vCenter Server.
- Attackers are leveraging these vulnerabilities to install Reverse SSH tools, establishing persistent connections and remote control over systems.
- All administrators must update security patches immediately, as real-world attacks are already occurring.

Reports indicate an ongoing cyberattack campaign targeting Critical Remote Code Execution (RCE) vulnerabilities in VMware vCenter Server, a widely used virtualization management platform worldwide.

βš™οΈ Attack Technique
Attackers are exploiting CVE-2024-37079 and CVE-2024-37080, which are Heap-overflow vulnerabilities, to breach systems. Once successful, the attackers install Reverse SSH tools on the compromised servers. This technique is highly dangerous as it creates a connection tunnel from within the victim's network back to the attacker's server, allowing them to bypass firewalls and organizational security measures.

πŸ’£ Potential Impact
Successful embedding of Reverse SSH grants attackers persistent access to the vCenter system, allowing them to regain control whenever desired. As vCenter Server is the heart of all virtualization systems, if compromised, attackers can control all Virtual Machines (VMs), access critical data, steal information, or even use it as a base to further attack other systems within the network, causing widespread damage.

πŸ›‘οΈ Recommendations for Administrators
VMware has released patches to address these vulnerabilities. All IT/System Administrators are advised to check the version of their vCenter Server and apply the security patches as soon as possible. Do not delay, as this is not merely a theoretical alert but an active attack campaign currently underway.

πŸ’¬ Have any administrators updated their vCenter Server patches yet? Feel free to share your status or any issues encountered.

Let’s build what’s next

Better IT starts with understanding your business.

Tell our engineers what you need and receive an initial recommendation at no cost.