Technology newsroom
Broadcom Issues Urgent Patch! Closes 3 Critical VMware Vulnerabilities Risk Auth Bypass, RCE, and VM Escape
Broadcom has released urgent patches for 3 critical vulnerabilities in VMware products affecting ESXi, vCenter, Workstation, and Fusion, which could lead to authentication bypass, remote code execution, and VM escape. System administrators should update immediately.
π Key Highlights:
- 3 critical vulnerabilities found in VMware ESXi, vCenter, Workstation, and Fusion products, with a maximum severity of CVSS 9.8.
- The vulnerabilities allow malicious actors to bypass authentication, execute code remotely (RCE), and escape from a VM to control the host (VM Escape).
- Broadcom, as the parent company, has released security patches. It is recommended that administrators update as urgently as possible to prevent damage.
Broadcom has announced a significant security update to address several vulnerabilities in popular VMware products, affecting ESXi, vCenter Server, Workstation, and Fusion. Among these, three are classified as critical, posing a high risk to organizations utilizing these virtualization systems.
π¨ The first critical vulnerability is CVE-2024-59309, with a high severity score of 9.8 (CVSS). This is an Authentication Bypass vulnerability in VMware vCenter Server, which allows attackers with network access to vCenter to bypass the authentication process and gain unauthorized access to the system. This is a major gateway that could lead to complete system compromise.
π» The second vulnerability is CVE-2024-59310, a Heap-overflow vulnerability in the DCERPC protocol of ESXi. Malicious actors who already have privileges on a Virtual Machine (VM) can exploit this vulnerability to attack the ESXi host directly, potentially leading to successful Remote Code Execution on the host.
π¨ And the last critical vulnerability is CVE-2024-59311, a Use-after-free vulnerability related to the vbluetooth device, affecting ESXi, Workstation, and Fusion. This vulnerability allows attackers with Local Admin privileges on a VM to exploit it to escape the VM's confinement (VM Escape) and take control of the Hypervisor or the host machine running that VM.
The discovery of these 3 critical vulnerabilities is an urgent matter for all IT administrators, as they are prime targets for hackers to penetrate organizational infrastructure systems. Therefore, it is highly recommended to check and apply security patches from Broadcom as soon as possible.
π¬ Who uses VMware? When do you plan to update the patches? Don't forget to check your systems!