Broadcom Releases Security Updates for VMware ESXi, Workstation, Fusion, and vCenter Server
Advisory addresses three security vulnerabilities that could result in DoS, RCE, or partially reading arbitrary files
Summary
Advisory addresses three security vulnerabilities that could result in DoS, RCE, or partially reading arbitrary files
Affected platforms
The following platforms are known to be affected:
Threat details
Introduction
Broadcom has released an advisory that addresses three security vulnerabilities in VMware ESXi, VMware vCenter Server, VMware Cloud Foundation, VMware Workstation, and VMware Fusion.
VMware ESXi is an enterprise-class hypervisor, VMware vCenter server is a centralised virtual machine manager, and Cloud Foundation is a platform for the provision of cloud environments. Workstation is a line of desktop hypervisor products that let users run virtual machines, containers, and Kubernetes clusters and VMware Fusion is the hypervisor developed for macOS systems.
Vulnerability details
- CVE-2024-22273 The storage controllers on VMware ESXi, Workstation, and Fusion have out-of-bounds read/write vulnerability. An attacker with access to a virtual machine with storage controllers enabled may exploit this issue to create a denial-of-service (DoS) condition or execute code on the hypervisor from a virtual machine in conjunction with other issues.
- CVE-2024-22274 The vCenter Server contains an authenticated remote code execution (RCE) vulnerability. An attacker with administrative privileges on the vCenter appliance shell may exploit this issue to run arbitrary commands on the underlying operating system.
- CVE-2024-22275 The vCenter Server contains a partial file read vulnerability. An attacker with administrative privileges on the vCenter appliance shell may exploit this issue to partially read arbitrary files containing sensitive data.
Proof-of-concept exploit code has been published for CVE-2024-22274
Proof-of-concept exploit code for CVE-2024-22274 has been publicly released. Exploitation is considered more likely.
Threat updates
Date | Update |
---|---|
9 Jul 2024 |
CVE-2024-22274 proof-of-concept released
The cyber alert has been updated to reflect this change. |
Remediation advice
Affected organisations are encouraged to review Broadcom's VMware advisory VMSA-2024-0011 and apply the relevant updates.
Definitive source of threat updates
CVE Vulnerabilities
Last edited: 9 July 2024 2:42 pm