VMware has confirmed that a critical vCenter Server remote code execution vulnerability patched in October is now under active exploitation. vCenter Server is a management platform for VMware vSphere environments that helps administrators manage ESX and ESXi servers and virtual machines (VMs). "VMware has confirmed that exploitation of CVE-2023-34048 has occurred in the wild," the company said in an update added to the original advisory this week. The vulnerability was reported by Trend Micro vulnerability researcher Grigory Dorodnov and is caused by an out-of-bounds write weakness in vCenter's DCE/RPC protocol implementation. Attackers can exploit it remotely in low-complexity attacks with high confidentiality, integrity, and availability impact that don't require authentication or user interaction. Due to its critical nature, VMware has also issued security patches for multiple end-of-life products without active support. Network access brokers like to take over VMware servers and then sell on cybercrime forums to ransomware gangs for easy access to corporate networks. Many ransomware groups (like Royal, Black Basta, LockBit, and, more recently, RTM Locker, Qilin, ESXiArgs, Monti, and Akira) are now known for directly targeting the victims' VMware ESXi servers to steal and encrypt their files and demand huge ransoms. According to Shodan data, more than 2,000 VMware Center servers are currently exposed online, potentially vulnerable to attacks and exposing corporate network...
VMware confirms critical vCenter flaw now exploited in attacks
BleepingComputer
·Sergiu Gatlan
·Published Jan 19, 2024
·Updated
Affected Software
1 affected component
VMware vCenter Server
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses a critical remote code execution vulnerability in VMware vCenter Server that is being actively exploited.
2
What security implications are discussed in the article?
The article highlights the risk of unauthorized access and system compromise due to the exploited vulnerability in vCenter Server.
3
What products or software are affected?
The affected software identified in the article is VMware vCenter Server.
4
When was the vulnerability patched?
The vulnerability was patched in October before being detected in active exploitation.
5
What should users of vCenter Server do in response to the vulnerability?
Users of vCenter Server are advised to apply the latest patches and implement security measures to mitigate exploitation risks.