VMware Warns of Ransomware-Friendly Bug in vCenter Server
#1
Information 
Quote:VMware has released a security update that includes patches for 19 CVE-numbered vulnerabilities that affect the company’s vCenter Server virtualization management platform and its hybrid Cloud Foundation platform for managing VMs and orchestrating containers.
 
They’re all serious, but one – CVE-2021-22005, a critical arbitrary file upload vulnerability in the Analytics service that’s been assigned the maximum CVSSv3 base score of 9.8 – is uber nasty.
 
“This vulnerability can be used by anyone who can reach vCenter Server over the network to gain access, regardless of the configuration settings of vCenter Server,” said Bob Plankers, Technical Marketing Architect at VMware.
 
092321 0935 UPDATE: On Wednesday afternoon, Bad Packets revealed that it had spotted threat actors scanning for vulnerable vCenter servers that haven’t yet applied VMware’s CVE-2021-22005 update. There’s no exploit code that’s been made public – yet – but within hours of VMware’s disclosure, threat intelligence firm Bad Packets began to see attackers scanning some of its VMware honeypots for the critical vulnerability.

Read more: VMware Warns of Ransomware-Friendly Bug in vCenter Server | Threatpost
[-] The following 1 user says Thank You to silversurfer for this post:
  • harlan4096
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
Malwarebytes 5.1.11.139
  Malwarebytes 5....Mohammad.Poorya — 16:42
Thunderbird Nebula Version 128.3.2 (esr)
Thunderbird Nebula...harlan4096 — 08:27
Bitdefender 27.0.41.210
Bitdefender’s most...harlan4096 — 08:26
CCleaner 6.29.11342 (16 Oct 2024)
CCleaner 6.29.1134...harlan4096 — 08:24
Intel releases Extreme Tuning Utility 10...
Intel XTU 10 relea...harlan4096 — 08:23

[-]
Birthdays
Today's Birthdays
avatar (46)maggiebz16
Upcoming Birthdays
avatar (46)Michaelaceve
avatar (36)QuadirLigh
avatar (37)Mblippek
avatar (40)guerigGep
avatar (43)viecontAceve
avatar (46)vikgoMam
avatar (39)Michaelcrini

[-]
Online Staff
There are no staff members currently online.

>