Software

Virtualization

VMware patches remote make-me-root holes in vCenter Server, Cloud Foundation

Bug reports made in China


Broadcom has emitted a pair of patches for vulnerabilities in VMware vCenter Server that a miscreant with network access to the software could exploit to completely commandeer a system. This also affects Cloud Foundation.

The first flaw, CVE-2024-38812, is a heap overflow vulnerability in the Distributed Computing Environment/Remote Procedure Calls (DCERPC) system that could be exploited over the network to achieve remote code execution on unpatched systems. Corrupting the heap could allow an attacker to execute arbitrary code on the system. Broadcom rates it as a critical fix and it has a CVSS score of 9.8 out of 10.

The second one, CVE-2024-38813, is a privilege escalation flaw that ranks a CVSS score of 7.5 and one that VMware-owned Broadcom rates as important. Someone with network access to VMware's vulnerable software could exploit this to gain root privileges on the system.

We can imagine a miscreant with network access using CVE-2024-38812 to gain code execution on a box, and then using CVE-2024-38813 to step up to administrative control. This scenario isn't explicitly outlined in the advisory though Broadcom chose to pair the flaws together in its advisory today and FAQ.

Versions 7 and 8 of vCenter Server and versions 4 and 5 of VMware Cloud Foundation are at risk and Broadcom warns there is no practical workaround for these bugs. In other words, get patching.

The blunders are addressed in vCenter Server versions 8.0 U3b and 7.0 U3s, and Cloud Foundation with async patches to 8.0 U3b and 7.0 U3s.

The discovery of both flaws stemmed from the Matrix Cup Cyber Security Competition, held in June in China, which was organized by 360 Digital Security Group and Beijing Huayunan Information Technology Company. Over 1,000 teams competed to report holes in products for $2.75 million in prizes.

Zbl and srs of Team TZL at Tsinghua University were credited with discovering the bugs, which were disclosed to Broadcom to patch.

The team bagged the competition's Best Vulnerability Award, along with a $59,360 payday, showing once again that bug bounties and competitive hacking really work. ®

Send us news
1 Comment

Rackspace moving some of its own workloads off VMware to address bigger Broadcom bills

New home, Platform9, says it’s also helping a Fortune 500 company to migrate 40,000 VMs

Talk of Broadcom and TSMC grabbing pieces of Intel lights fire under investors

Chipzilla's design and manufacturing limbs said to be on the table

Broadcom reportedly investigates acquiring Intel’s chip design biz

Shhh. Don’t tell Hock Tan about those Xeons that unlock functions when you pay a fee

Ivanti endpoint manager can become endpoint ravager, thanks to quartet of critical flaws

PoC exploit code shows why this is a patch priority

Oops, some of our customers' Power Pages-hosted sites were exploited, says Microsoft

Don't think this is SaaS and you can relax: Redmond wants a few of you to check your websites

VMware plugs steal-my-credentials holes in Cloud Foundation

Consider patching soon because cybercrooks love to hit vulnerable tools from Broadcom's virtualization giant

Fear of the unknown keeps Broadcom's VMware herd captive. Don't be cowed

Prisoners of ware can’t escape by looking at each other. Form a committee, soldiers

Cisco patches two critical Identity Services Engine flaws

One gives root access, the other lets you steal info and reconfig nodes, in the right (or should that be wrong) circumstances

VMware users gripe over 3-year commitment to renew licenses

Chips and software giant Broadcom says it's 'flexible and open' on licensing terms, but customers disagree

Google patches odd Android kernel security bug amid signs of targeted exploitation

Also, Netgear fixes critical router, access point vulnerabilities

VMware migrations will be long, expensive, risky, Gartner warns

And possibly even more so if you don’t start planning yours soon

Broadcom filing mentions major VMware Cloud Foundation releases in March and July

Will they make price rises palatable? Or bring more of what new Netflix lawsuit calls Broadcom's ‘Buy. Chop up. Raise prices' business plan?