By Interestana AI Editorial — AI-drafted, human-overseen. How we report
Broadcom Patches Critical VMware Vulnerabilities
Broadcom has released security updates to address five vulnerabilities affecting VMware products, including vCenter, ESX, Workstation, and Fusion. Three of these vulnerabilities are classified as critical and could allow attackers to bypass authentication mechanisms, execute arbitrary code on affected systems, or achieve virtual machine escapes, granting them access to the host system. The company has provided patches and workarounds to mitigate these risks for users of its virtualization software.
One of the critical vulnerabilities, identified as CVE-2024-22252, is an authentication bypass flaw in the vCenter Server's DCERPC interface. This vulnerability could enable an unauthenticated attacker to gain administrative access to the vCenter Server. Another critical flaw, CVE-2024-22253, is a heap-based buffer overflow in the DCERPC service of vCenter Server, which could lead to arbitrary code execution. The third critical vulnerability, CVE-2024-22254, is a use-after-free vulnerability in the Workstation and Fusion products that could permit an attacker to achieve a virtual machine escape.
In addition to the three critical vulnerabilities, Broadcom also addressed two high-severity flaws. CVE-2024-22255 is a buffer overflow in the Workstation and Fusion products that could lead to arbitrary code execution. CVE-2024-22256 is a heap-based buffer overflow in the vCenter Server's DCERPC service, also potentially leading to arbitrary code execution. These vulnerabilities underscore the ongoing challenges in securing complex software environments, particularly those involving virtualization technologies that are foundational to modern IT infrastructure.
VMware, now a part of Broadcom following the acquisition completed in November 2023, is a leading provider of cloud computing and virtualization software. Its products are widely used by enterprises to manage and deploy virtual machines, enabling greater efficiency and flexibility in IT operations. The widespread adoption of VMware technologies means that vulnerabilities within its software can have a significant impact across a large number of organizations. The company's security advisories typically detail the affected product versions and provide guidance on applying the necessary patches. Users are strongly advised to implement these updates promptly to protect their environments from potential exploitation. The disclosure of these vulnerabilities highlights the importance of continuous security monitoring and proactive patching strategies for all software, especially critical infrastructure components.
Original source — read the full reporting at the publisher:
Read on BleepingComputerGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.