Enterprise IT Support β€’ Bangkok & Nationwide

Technology newsroom

🚨 VMware Users Alert! Broadcom Releases Urgent Patches for 3 Critical Vulnerabilities, Risking System Bypass and VM Escape

Broadcom has released urgent patches for VMware products to address 5 vulnerabilities, 3 of which are critical. These vulnerabilities could allow hackers to bypass authentication, execute remote code, or even escape from a Virtual Machine to control the host system.

Edited by SyncTech Solution Published Source Original source
🚨 VMware Users Alert! Broadcom Releases Urgent Patches for 3 Critical Vulnerabilities, Risking System Bypass and VM Escape

πŸ“Œ Key Highlights:
- Broadcom has released security updates for several VMware products to fix 5 vulnerabilities, 3 of which are critical.
- The most severe vulnerabilities are VM Escapes (CVE-2024-22252, CVE-2024-22253), allowing hackers to break out of a Virtual Machine and directly control the host machine.
- Another critical vulnerability (CVE-2024-22254) allows attackers to bypass authentication on vCenter Server to gain system access.

Broadcom, the parent company of VMware, has issued an important security advisory, releasing patches to fix 5 vulnerabilities in popular products such as VMware vCenter, ESXi, Workstation, and Fusion. Of these, 3 are rated as critical severity, potentially having a massive impact on organizations that use them.

πŸ’» Deep Dive into Critical Vulnerabilities
The most concerning vulnerabilities are a group of Use-after-free flaws in the XHCI and UHCI USB controllers, namely CVE-2024-22252 and CVE-2024-22253, with a high severity score of 9.3/10. These vulnerabilities allow attackers with access to a Virtual Machine to run malicious code to escape (Escape) from the virtual environment to the operating system of the host machine running that VM, effectively seizing control of the entire host server.

Another critical vulnerability, CVE-2024-22254, with a severity score of 9.8/10, is an Out-of-bounds write flaw in the DCERPC protocol of vCenter Server. This vulnerability allows attackers on the same network as the vCenter Server to send specially crafted packets to initiate an attack, potentially leading to Remote Code Execution (RCE) without requiring authentication.

πŸ›‘οΈ Recommendations and Mitigation
Broadcom and VMware advise all system administrators to update these newly released security patches as soon as possible to prevent the risk of attacks. Organizations that directly expose vCenter Server or ESXi to the internet are at particularly high risk. Leaving these vulnerabilities unpatched is akin to leaving a backdoor open for malicious actors to cause damage to organizational data and IT infrastructure.

πŸ’¬ Have you checked and updated VMware security patches in your systems? Feel free to share your experiences or questions.

Let’s build what’s next

Better IT starts with understanding your business.

Tell our engineers what you need and receive an initial recommendation at no cost.