VMware issues 'emergency change' for vCenter Server exploits
Affects vCenter Server versions 6.5, 6.7 and 7.0.
Stay updated with breaking news from Sphere Client. Get real-time updates on events, politics, business, and more. Visit us for reliable news and exclusive interviews.
Affects vCenter Server versions 6.5, 6.7 and 7.0.
The company warns that ransomware gangs are primed to exploit two flaws to conduct remote code execution attacks
VMware Urges Rapid Patching for Serious vCenter Server Bug Compliance Compliance Twitter Get Permission VMware is warning all vCenter Server administrators to patch their software to fix both a serious vulnerability that could be used to execute arbitrary code, as well as a separate authentication flaw. Administrators use vCenter Server to manage installations of vSphere, which is VMware's virtualization platform. The vulnerabilities need "your immediate attention if you are using vCenter Server," VMware's Bob Plankers says in a blog post. "All environments are different, have different tol...
Critical RCE Vulnerability Discovered in VMware vCenter Server May 26, 2021 11:32 GMT · Comment VMware VMware has released fixes to address a significant vulnerability in vCenter System that can be exploited by an attacker to execute arbitrary code on the server. The vulnerability, identified as CVE-2021-21985 (CVSS score 9.8), originates from a lack of input validation in the Virtual SAN (vSAN) plug-in Health Check. This plug-in is enabled by default in vCenter Server. VMware said in its advisory that "A malicious actor with network access to port 443 may exploit th...
The vulnerabilities were discovered by Mikhail Klyuchnikov, senior web application security researcher at Positive Technologies. "There is already scanning of the internet for this vulnerability," he told DCK. When Positive Technologies released its report on the vulnerability Wednesday, the research firm was able to find more than 6,000 VMware vCenter devices worldwide that were accessible via the internet and had this vulnerability, a quarter of them located in the US. While exposed systems are the highest and immediate risk, the bigger potential harm comes from internal systems on networks...