VMware Security Advisory
VMware has disclosed a new vulnerability, covered by VMware Security Advisory 2024-0012. The issues are rated 7.8 to 9.8 on the CVSS scale.
VMware has disclosed a new vulnerability. It is covered by VMware Security Advisory 2024-0012 and the issues are rated 7.8 to 9.8 on the CVSS scale. The most severe one (CVSS 9.8) should be closed with the available update as soon as possible. Customers with Skyline active should already have been notified of the critical finding.
VMSA-2024-0012
The published vulnerabilities (CVE-2024-37079, CVE-2024-37080, CVE-2024-37081) let an attacker who is logged in locally on the vCenter appliance obtain root rights. Only vCenter is affected. Further detail and the fixed version are at VMware.
VMware reports no known attacks so far. With the vulnerabilities now published that can change within hours. Both soulTec and VMware recommend patching the affected systems immediately. If you need a hand, we are here for you.