VMware Patches Three Critical Vulnerabilities Including VM Escape Flaw

Broadcom releases urgent security updates for five vulnerabilities affecting VMware vCenter, ESX, Workstation, and Fusion. Three of these flaws carry critical severity ratings, including two vCenter vulnerabilities scored at 9.8 on the CVSS scale. The bugs also impact products that contain vCenter or ESX, such as VMware Cloud Foundation and vSphere Foundation. Broadcom warns that organizations running versions older than the patched releases should assume they are vulnerable and take immediate action.

The two most severe issues reside in vCenter. The first is an authentication bypass in the VMware Directory Service that lets an unauthenticated attacker with network access gain entry to the system. The second is a directory traversal vulnerability in the vCenter Syslog server that allows remote code execution. A third critical flaw, rated 9.3, exists in the VMXNET3 virtual network adapter and enables an attacker with local admin privileges inside a VM to execute code on the ESX host, effectively achieving a virtual machine escape.

The remaining two vulnerabilities carry lower severity ratings but still pose real risks. An out-of-bounds read flaw in ESX, Workstation, and Fusion allows attackers with VM deployment privileges to disclose information or trigger denial-of-service conditions on the host. The final vulnerability stems from insufficient logging, letting a malicious ESX administrator perform certain operations without leaving an audit trail. Administrators across all affected VMware environments should prioritize applying the available patches as soon as possible.

Read More at the original source →