iTnews Asia
  • Home
  • News
  • Security

VMware warns to patch now against exploitable bugs

VMware warns to patch now against exploitable bugs

Exploit code published on GitHub.

By Richard Chirgwin on Oct 25, 2023 11:40AM

VMware is warning that high-severity bugs first disclosed last week now have proof-of-concept (PoC) exploit code available, and need to be patched.

The company’s October 19 advisory for CVE-2023-34051 (an authentication bypass bug) and CVE-2023-34052 (a deserialisation vulnerability) has been updated to reflect the existence of the exploit code.

The two bugs affect its Aria Operations for Logs (formerly vRealize Logs) software.

According to a technical analysis by Horizon3, the latest bugs arose because of an incomplete fix for the issues disclosed earlier this year, in this advisory.

VMware closed a bug in its Thrift services, which Horizon3 explained was meant to make the other vulnerabilities unreachable.

“Since the patch only blocks access to Thrift services by IP and did not fix the other CVEs in VMSA-2023-0001, all an attacker needs to do is spoof their IP address and use the previous attack,” Horizon3 said.

“For this attack to work we need: At least two instances of VMware vRealize Log Insight in a master / worker configuration; [and] An attacker machine that uses the same source IP address as the worker node (if attacking the master).”

The researchers noted that while the attack was straightforward, "it relies on the attacker having compromised an existing host in the environment and having the sufficient permissions to add an additional static IP to an existing interface or add an additional interface.”

Horizon3’s PoC code is on GitHub.

To reach the editorial team on your feedback, story ideas and pitches, contact them here.
Copyright © iTnews.com.au . All rights reserved.
Tags:
horizon3 security vmware

Related Articles

  • The best way to outsmart your threat actors is to think like one
  • How cybercriminals are exploiting LLMs to harm your business
  • Is identity now the next parameter of cybersecurity breaches?
  • Cybersecurity threats CISOs should be most worried about in 2025
Share on Twitter Share on Facebook Share on LinkedIn Share on Whatsapp Email A Friend

Most Read Articles

The best way to outsmart your threat actors is to think like one

The best way to outsmart your threat actors is to think like one

What are the most pressing cyber security concerns going into 2025?

What are the most pressing cyber security concerns going into 2025?

Malaysia ramps up cyber security defense to stem rising fraud and ransomware attacks

Malaysia ramps up cyber security defense to stem rising fraud and ransomware attacks

How cybercriminals are exploiting LLMs to harm your business

How cybercriminals are exploiting LLMs to harm your business

All rights reserved. This material may not be published, broadcast, rewritten or redistributed in any form without prior authorisation.
Your use of this website constitutes acceptance of Lighthouse Independent Media's Privacy Policy and Terms & Conditions.