Security

Patches

VMware by Broadcom warns of two critical vCenter flaws, plus a nasty sudo bug

Specially crafted network packet could allow remote code execution and access to VM fleets


VMware by Broadcom has revealed a pair of critical-rated flaws in vCenter Server – the tool used to manage virtual machines and hosts in its flagship Cloud Foundation and vSphere suites.

Announced late on Monday night, Pacific Time, the critical-rated flaws are CVE-2024-37079 and CVE-2024-37080, both of which scored 9.8 on the ten-point Common Vulnerability Scoring System v3 scale.

VMware's security bulletin describes both of the flaws as "heap-overflow vulnerabilities in the implementation of the DCE/RPC protocol" that mean "A malicious actor with network access to vCenter Server may trigger these vulnerabilities by sending a specially crafted network packet potentially leading to remote code execution."

DCE/RPC (which stands for Distributed Computing Environment/Remote Procedure Calls) is a means of calling a procedure on a remote machine as if it were a local machine – just the ticket when managing virtual machines.

However, the prospect of an attacker using the flaws to run code on vCenter Server and drive fleets of VMs and hosts is deeply unpleasant.

VMware has published a resource for its customers that states the Broadcom business unit "is not currently aware of exploitation 'in the wild'."

The good news is that patched versions of vCenter Server and Cloud Foundation are already available.

The bad news is that VMware hass not considered whether the flaws impact older versions of vSphere – meaning versions 6.5 and 6.7, which exited support in October 2022 but are still widely used, may be impacted but won't be fixed.

Further unwelcome news is that VMware also revealed a third flaw – CVE-2024-37081 – described as "local privilege escalation vulnerabilities due to misconfiguration of sudo." This one is rated important, with a score of 7.8, as it could mean "An authenticated local user with non-administrative privileges may exploit these issues to elevate privileges to root on vCenter Server Appliance."

The versions of vCenter Server and Coud Foundation affected by these flaws were released before Broadcom took over VMware – a tidbit we mention as some doomsayers have suggested job cuts at the virty giant could impact product quality.

VMware has tipped its hat to Matei "Mal" Badanoiu of Deloitte Romania for finding the flaws. ®

Send us news
8 Comments

Broadcom promised to reform VMware so it enables better hybrid clouds. Will it deliver?

It needs to – Virtzilla's customers, allies, and enemies are all pondering off-ramps and trying to lure unhappy users

Broadcom has brought VMware down to earth and that’s welcome

But users aren’t optimistic it will land softly

Veeam debuts its Proxmox backup tool – and reveals outfit using it to quit VMware

More help for Nutanix, too

Public clouds are 'dirty' about VMware's on-prem push, says Broadcom CEO Hock Tan

Virtzilla's sales swing decisively to the Cloud Foundation bundle

VMware revenue bounces for Broadcom, chips were a little undercooked

CEO says market for non-AI silicon has bottomed out

VMware reveals how it will deliver Broadcom's unified hybrid cloud … sometime soon

Claims just two management consoles will emerge

Broadcom boss Hock Tan says public cloud gave IT departments PTSD

While datacenter silos have left you ‘so screwed’

Cisco's Smart Licensing Utility flaws suggest it's pretty dumb on security

Two critical holes including hardcoded admin credential

Gartner warns Omnissa – formerly VMware's end-user compute biz – represents new risks

Weak roadmap, tricky migration path, and Broadcom dependencies add up to uncertainty

Microsoft hosts a security summit but no press, public allowed

CrowdStrike, other vendors, friendly govt reps…but not anyone who would tell you what happened

AT&T sues Broadcom for 'breaking' VMware support extension contract

Telco giant slams silicon-and-software shop for trying to bully it into buying software it doesn't want or need, at huge prices

Security boom is over, with over a third of CISOs reporting flat or falling budgets

Good news? Security is still getting a growing part of IT budget