AI
AI

VMware Addresses Security Vulnerability with Two Patches

Photo credit: www.csoonline.com

A recently identified vulnerability in vCenter Server poses a significant security threat, stemming from a heap overflow associated with the DCERPC (Distributed Computing Environment / Remote Procedure Call) protocol. This flaw allows an attacker with network access to the vCenter Server to exploit the vulnerability by sending a specifically crafted network packet, potentially leading to remote code execution. The severity of this vulnerability has been highlighted with a CVSS score of 9.8 out of 10, underscoring the gravity of the threat it presents.

Discovery by Chinese Hackers

The first patch addressing this issue was rolled out in September 2024, following its discovery during the 2024 Matrix Cup, a notable hacking competition held in China. VMware credited research teams participating in this event for unveiling the vulnerability. The Matrix Cup, which took place in June 2024, is organized by Chinese cybersecurity company Qihoo 360 alongside Beijing Huayun’an Information Technology. This competition focuses on identifying zero-day vulnerabilities across various platforms, including operating systems, smartphones, enterprise software, browsers, and security products.

This incident highlights the proactive role that ethical hacking competitions can play in enhancing cybersecurity awareness and fostering the discovery of critical vulnerabilities. By uncovering such flaws, security researchers can help organizations mitigate risks and bolster defenses against potential exploitation by malicious actors.

Source
www.csoonline.com

Related by category

Navigating the CISO Cloud Security Dilemma: Purchase, Build, or a Combination of Both?

Photo credit: www.csoonline.com Cloud security is not solely focused on...

Cyberkriminelle optimieren ihre Angriffsstrategien.

Photo credit: www.csoonline.com Cyberkriminalität zielt zunehmend auf kleine und mittelständische...

CNAPP-Kaufberatung

Photo credit: www.csoonline.com Cloud-Sicherheit bleibt ein anspruchsvolles Thema, vor allem,...

Latest news

Putin States Renaming to Stalingrad is a Decision for Local Residents

Photo credit: www.yahoo.com (Reuters) - Russian President Vladimir Putin stated...

Snake Disrupts Japan’s Busiest Bullet Train Route, Causing Delays

Photo credit: www.theguardian.com Japan's busiest bullet train service experienced a...

Strategic Voting Emerges to ‘Block Reform’ and Undermine Farage in the 2025 Local Elections

Photo credit: www.theguardian.com A new trend in tactical voting may...

Breaking news