VMware was forced to patch critical vCenter Server RCE flaw for a second time after a bad patch

VMware has been forced to release a second patch for a serious security vulnerability in its vCenter Server platform after an initial release failed to resolve the issue.

Users are advised to apply the solution immediately as the identified errors are quite dangerous and there is no proper solution for them.

The good news is that there is currently no evidence of abuse in the wild, so perhaps the miscreants haven’t picked them up yet. However, since there are no solutions and companies are notoriously slow to patch, it’s only a matter of time before they do.

No solution

“All customers are strongly encouraged to apply the patches currently listed in the Response Matrix,” the advisory reads.

In mid-September 2024, VMware issued a security advisory claiming that it had patched two flaws in vCenter Server that could have given threat actors the ability to perform remote code execution (RCE). These flaws were tracked as CVE-2024-38812 and CVE-2024-38813.

The former affects vCenter 7.0.3, 8.9.2, and 8.0.3, as well as all versions of vSphere or VMware Cloud Foundation before the versions listed above. It was given a severity score of 9.8 (critical) because it can be exploited without user interaction, and because it grants RCE capabilities to a threat actor sending a tailored network packet.

The latter, on the other hand, is a 7.5 severity error, which allows escalation of root privileges.

According to The registrythese two flaws are particularly dangerous when linked together, as a threat actor can first remotely execute malicious code and then gain administrative privileges to cause even more damage. Furthermore, VMware systems are a popular target for ransomware operators and state-sponsored threat actors, given their ubiquity in the business world.

Both vulnerabilities were first discovered by Team TZL from Tsinghua University, during the Matrix Cup Cyber ​​Security Competition, held in China earlier this year, the publication said.

Via The Register

More from Ny Breaking

Related Post