Category: Security Advisory

VMware vCenter Server Vulnerability Patch Released: VMSA-2024-0019

Security Advisory

VMware has issued a critical patch for vCenter Server, addressing two significant vulnerabilities: CVE-2024-38812 and CVE-2024-38813, both of which pose serious security risks. These vulnerabilities, with a CVSSv3 score of 9.8 and 7.5 respectively, affect the DCERPC protocol and could lead to remote code execution and privilege escalation. Vulnerabilities Overview: 1. CVE-2024-38812: Heap-Overflow Vulnerability 2.…

Read more

VMSA-2024-0021: Addressing SQL Injection Vulnerability in VMware HCX (CVE-2024-38814)

Security Advisory

On October 16, 2024, VMware released a security advisory (VMSA-2024-0021) regarding a high-severity SQL injection vulnerability (CVE-2024-38814) found in VMware HCX, a crucial component for hybrid cloud extension solutions. This vulnerability, which could lead to unauthorized remote code execution, has a CVSSv3 base score of 8.8, emphasizing the importance of applying the recommended patches as…

Read more

VMware Security Advisory: VMSA-2024-0019 – Critical Vulnerabilities in VMware vCenter Server

Security Advisory

On September 17, 2024, VMware issued a critical security advisory (VMSA-2024-0019) addressing two significant vulnerabilities affecting VMware vCenter Server and VMware Cloud Foundation. The vulnerabilities—CVE-2024-38812 and CVE-2024-38813—could allow attackers to execute remote code and escalate privileges. VMware has released updates to mitigate these threats, urging users to apply the patches immediately. Impacted Products The vulnerabilities…

Read more

APT INC: The Rebranded Threat Continuing VMware ESXi Attacks

Security Advisory

The notorious SEXi ransomware operation, previously known for its relentless attacks on VMware ESXi servers, has recently rebranded itself as APT INC. This cybercriminal group has continued its assault on numerous organizations, maintaining its focus on VMware ESXi servers with renewed vigor. The ransomware operation began in February 2024, leveraging the leaked Babuk encryptor to…

Read more

Urgent Alert: Patch Your VMware vCenter Server Now to Prevent Major Security Breach VMSA-2024-0012!

Security Advisory

Attention all VMware users! There’s a crucial patch for VMware vCenter Server you need to be aware of right now. This patch addresses significant vulnerabilities, so updating your vCenter Server is essential. I’ve already navigated the patching process and am here to guide you through it. We’ll start by examining the VMware vCenter Server critical…

Read more

TPM 2.0 on ESXi Hosts: Enhancing Security and Efficiency

Security Advisory

VMware’s vSphere 6.7 introduced support for TPM 2.0, marking a significant step in enhancing host security for ESXi. As the technology evolved, subsequent updates, such as vSphere 8 Update 1, further integrated features like Quick Boot to optimize system performance and reduce downtime. This article delves into the workings of TPM 2.0 on ESXi hosts,…

Read more

Understanding UEFI Secure Boot and Its Implementation in ESXi

Security Advisory

The Unified Extensible Firmware Interface (UEFI) has become a crucial component in modern computing, serving as the bridge between the operating system and the firmware of a device. Among its many features, UEFI Secure Boot stands out as a vital security measure, ensuring that only verified and trusted software is loaded during the boot process.…

Read more

The New Linux Variant of TargetCompany Ransomware: focuses on VMware ESXi

Security Advisory

In a significant development in the cybersecurity landscape, researchers have identified a new Linux variant of the notorious TargetCompany ransomware family. This variant specifically targets VMware ESXi environments using a sophisticated custom shell script to deliver and execute malicious payloads. Known by several aliases, including Mallox, FARGO, and Tohnichi, the TargetCompany ransomware operation has been…

Read more

Securing Your VMware Environment: A Deep Dive into VMSA-2024-0006

Security Advisory

VMware has recently shed light on a slew of vulnerabilities hitting close to home for its mainline products: VMware ESXi, Workstation, Fusion, and Cloud Foundation. In this blog post, we’re diving deep into VMware Security Advisory VMSA-2024-0006, breaking down the vulnerabilities, understanding what they mean for you, and laying out exactly what you need to…

Read more

Critical Vulnerability in VMware Aria Automation: Understanding and Mitigating the Risk

Security Advisory

Impacted Products VMware’s product lineup, specifically VMware Aria Automation (formerly known as vRealize Automation) and VMware Cloud Foundation (incorporating Aria Automation), are currently in the spotlight due to a significant security vulnerability. Introduction A critical security concern, identified as a Missing Access Control vulnerability, has been discovered in Aria Automation. This issue was privately reported…

Read more