Technology newsroom
Global Attack Campaign! Hackers Target Critical Vulnerability on VMware vCenter - Warning: Patching Alone May Not Be Enough π¨
Global hackers are exploiting the critical vulnerability CVE-2023-34048 in VMware vCenter, enabling remote code execution. Experts warn that patching alone may be insufficient, as attackers may have already embedded backdoors.
π Key Takeaways:
- The CVE-2023-34048 vulnerability, rated Critical (9.8), allows attackers to execute remote code without authentication.
- Attacks began before VMware released patches for older, end-of-support vCenter Server versions (6.5 and 6.7), leaving many systems at risk.
- Experts warn that simply applying patches may not be enough; systems must be checked for lingering signs of intrusion.
A global cyberattack campaign is reportedly targeting a critical security vulnerability in VMware vCenter Server, a popular virtualization management platform. This vulnerability, identified as CVE-2023-34048, has a severity score of 9.8 out of 10, categorized as an out-of-bounds write vulnerability within the DCE/RPC protocol.
Of particular concern is that this vulnerability allows malicious actors to successfully execute arbitrary remote code (Remote Code Execution) on affected servers without requiring any authentication, enabling hackers to easily take control of systems.
π¨ Concerning Situation
Analysis indicates that threat actors began exploiting this vulnerability earlier this month, even before VMware released patch updates for older, end-of-support vCenter Server versions like 6.5 and 6.7. This means there was a period during which many systems were exposed to attacks without official protection.
π Why Patching May Not Be Enough
Security experts have warned system administrators that even after applying the latest security patches, it may not be entirely sufficient to mitigate this threat. The reason is that if your system was compromised before patching, attackers might have already embedded backdoors or established other forms of persistence within the system. This allows them to regain control of your system even after the initial vulnerability has been closed. Therefore, it is crucial to thoroughly inspect systems for signs of intrusion in conjunction with patch updates.
π¬ Which VMware vCenter versions does your organization use? Have you checked and applied the latest security patches?