VMware Issues Patches for Cloud Foundation, vCenter Server, and vSphere ESXi
ID: d417d0ba-7ccb-5fe2-b2fa-09b544dbe018
STIX ID: report--d417d0ba-7ccb-5fe2-b2fa-09b544dbe018
Feed Name: The Hacker News
**VMware critical vulnerabilities: remote code execution and local privilege escalation in vCenter Server (7.0/8.0); apply patches promptly.** VMware released updates addressing CVE-2024-37079 and CVE-2024-37080 (heap-overflow DCE/RPC issues, CVSS 9.8) that could allow remote code execution, and CVE-2024-37081 (sudo misconfiguration, CVSS 7.8) that allows local privilege escalation; affected versions are patched in 7.0 U3r, 8.0 U1e, and 8.0 U2d, and there are no known reports of active exploitation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
