* . *
  • About
  • Advertise
  • Privacy & Policy
  • Contact
Friday, August 8, 2025
Earth-News
  • Home
  • Business
  • Entertainment
    Themed Entertainment Design – Purdue Polytechnic

    Innovative Themed Entertainment Design: Creating Immersive Experiences

    Rachael Leigh Cook and Brandon Routh ‘Happy to Have Found Each Other’ Following Respective Divorces – yahoo.com

    Rachael Leigh Cook and Brandon Routh ‘Happy to Have Found Each Other’ Following Respective Divorces – yahoo.com

    ‘Billie Jean’ – Hyde Park Herald

    The Enduring Magic Behind ‘Billie Jean’ Revealed

    Hank Hill returns to a changed world in new ‘King of the Hill’ episodes – New Haven Register

    Hank Hill Navigates a Bold New World in Thrilling New ‘King of the Hill’ Episodes

    Exclusive | Fox Takes Stake in IndyCar Owner Penske Entertainment – The Wall Street Journal

    Exclusive | Fox Takes Stake in IndyCar Owner Penske Entertainment – The Wall Street Journal

    Go-to entertainment: why gaming was made for the toilet – The Guardian

    Why Gaming Is the Ultimate Way to Pass Time in the Bathroom

  • General
  • Health
  • News

    Cracking the Code: Why China’s Economic Challenges Aren’t Shaking Markets, Unlike America’s” – Bloomberg

    Trump’s Narrow Window to Spread the Truth About Harris

    Trump’s Narrow Window to Spread the Truth About Harris

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Trending Tags

    • Trump Inauguration
    • United Stated
    • White House
    • Market Stories
    • Election Results
  • Science
  • Sports
  • Technology
    MBU showcases student work at Occupational Therapy Technology Fair – WHSV

    Discover the Most Innovative Student Projects at the Occupational Therapy Technology Fair

    BlackSky Technology Inc. (BKSY) Reports Q2 Loss, Lags Revenue Estimates – Yahoo Finance

    BlackSky Technology Inc. Reports Q2 Loss, Misses Revenue Targets

    Improved Technology Access: A Key to Closing the Healthcare Gap for African Americans – BIOENGINEER.ORG

    LMI Expands Technology Org, Appoints New Leaders – GovCon Wire

    LMI Expands Technology Team with Dynamic New Leadership Appointments

    Midland Innovation and Technology Charter School closing down – CBS News

    Midland Innovation and Technology Charter School Closes Permanently

    Future Trends In HR Technology – Dataconomy

    Future Trends In HR Technology – Dataconomy

    Trending Tags

    • Nintendo Switch
    • CES 2017
    • Playstation 4 Pro
    • Mark Zuckerberg
No Result
View All Result
  • Home
  • Business
  • Entertainment
    Themed Entertainment Design – Purdue Polytechnic

    Innovative Themed Entertainment Design: Creating Immersive Experiences

    Rachael Leigh Cook and Brandon Routh ‘Happy to Have Found Each Other’ Following Respective Divorces – yahoo.com

    Rachael Leigh Cook and Brandon Routh ‘Happy to Have Found Each Other’ Following Respective Divorces – yahoo.com

    ‘Billie Jean’ – Hyde Park Herald

    The Enduring Magic Behind ‘Billie Jean’ Revealed

    Hank Hill returns to a changed world in new ‘King of the Hill’ episodes – New Haven Register

    Hank Hill Navigates a Bold New World in Thrilling New ‘King of the Hill’ Episodes

    Exclusive | Fox Takes Stake in IndyCar Owner Penske Entertainment – The Wall Street Journal

    Exclusive | Fox Takes Stake in IndyCar Owner Penske Entertainment – The Wall Street Journal

    Go-to entertainment: why gaming was made for the toilet – The Guardian

    Why Gaming Is the Ultimate Way to Pass Time in the Bathroom

  • General
  • Health
  • News

    Cracking the Code: Why China’s Economic Challenges Aren’t Shaking Markets, Unlike America’s” – Bloomberg

    Trump’s Narrow Window to Spread the Truth About Harris

    Trump’s Narrow Window to Spread the Truth About Harris

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Trending Tags

    • Trump Inauguration
    • United Stated
    • White House
    • Market Stories
    • Election Results
  • Science
  • Sports
  • Technology
    MBU showcases student work at Occupational Therapy Technology Fair – WHSV

    Discover the Most Innovative Student Projects at the Occupational Therapy Technology Fair

    BlackSky Technology Inc. (BKSY) Reports Q2 Loss, Lags Revenue Estimates – Yahoo Finance

    BlackSky Technology Inc. Reports Q2 Loss, Misses Revenue Targets

    Improved Technology Access: A Key to Closing the Healthcare Gap for African Americans – BIOENGINEER.ORG

    LMI Expands Technology Org, Appoints New Leaders – GovCon Wire

    LMI Expands Technology Team with Dynamic New Leadership Appointments

    Midland Innovation and Technology Charter School closing down – CBS News

    Midland Innovation and Technology Charter School Closes Permanently

    Future Trends In HR Technology – Dataconomy

    Future Trends In HR Technology – Dataconomy

    Trending Tags

    • Nintendo Switch
    • CES 2017
    • Playstation 4 Pro
    • Mark Zuckerberg
No Result
View All Result
Earth-News
No Result
View All Result
Home Technology

VMware by Broadcom warns of two critical vCenter flaws, plus a nasty sudo bug

June 18, 2024
in Technology
VMware by Broadcom warns of two critical vCenter flaws, plus a nasty sudo bug
Share on FacebookShare on Twitter

VMware by Broadcom has revealed a pair of critical-rated flaws in vCenter Server – the tool used to manage virtual machines and hosts in its flagship Cloud Foundation and vSphere suites.

Announced late on Monday night, Pacific Time, the critical-rated flaws are CVE-2024-37079 and CVE-2024-37080, both of which scored 9.8 on the ten-point Common Vulnerability Scoring System v3 scale.

VMware’s security bulletin describes both of the flaws as “heap-overflow vulnerabilities in the implementation of the DCE/RPC protocol” that mean “A malicious actor with network access to vCenter Server may trigger these vulnerabilities by sending a specially crafted network packet potentially leading to remote code execution.”

DCE/RPC (which stands for Distributed Computing Environment/Remote Procedure Calls) is a means of calling a procedure on a remote machine as if it were a local machine – just the ticket when managing virtual machines.

However, the prospect of an attacker using the flaws to run code on vCenter Server and drive fleets of VMs and hosts is deeply unpleasant.

VMware has published a resource for its customers that states the Broadcom business unit “is not currently aware of exploitation ‘in the wild’.”

Notorious cyber gang UNC3944 attacks vSphere and Azure to run VMs inside victims’ infrastructure

Patch now: Critical VMware, Atlassian flaws found

Patch now: Critical VMware, Atlassian flaws found

VMware urges emergency action to blunt hypervisor flaws

The good news is that patched versions of vCenter Server and Cloud Foundation are already available.

The bad news is that VMware hass not considered whether the flaws impact older versions of vSphere – meaning versions 6.5 and 6.7, which exited support in October 2022 but are still widely used, may be impacted but won’t be fixed.

Further unwelcome news is that VMware also revealed a third flaw – CVE-2024-37081 – described as “local privilege escalation vulnerabilities due to misconfiguration of sudo.” This one is rated important, with a score of 7.8, as it could mean “An authenticated local user with non-administrative privileges may exploit these issues to elevate privileges to root on vCenter Server Appliance.”

The versions of vCenter Server and Coud Foundation affected by these flaws were released before Broadcom took over VMware – a tidbit we mention as some doomsayers have suggested job cuts at the virty giant could impact product quality.

VMware has tipped its hat to Matei “Mal” Badanoiu of Deloitte Romania for finding the flaws. ®

>>> Read full article>>>
Copyright for syndicated content belongs to the linked Source : The Register – https://go.theregister.com/feed/www.theregister.com/2024/06/18/vmware_criticial_vcenter_flaws/

Tags: BroadcomtechnologyVMware
Previous Post

Tencent ponders banning infomercials hosted by ‘virtual humans’ on its flagship video service

Next Post

IMF suggests tax on AI’s CO2 emissions, but not AI itself

Icing‐related injuries in polar bears (Ursus maritimus) at high latitudes – Laidre – 2024 – Ecology – ESA Journals

Frozen Peril: The Devastating Impact of Icing Injuries on Polar Bears in the High Arctic

August 8, 2025
Carnegie Science Center launching new name in September – CBS News

Carnegie Science Center Unveils Exciting New Name This September

August 8, 2025
Petersburg youth explore Coho Creek for science education – Petersburg Pilot

Petersburg Youth Dive into Science with Hands-On Exploration of Coho Creek

August 8, 2025
Is there a path to healthier aging? What the latest research shows | Bodyworks – The Oklahoman

Is there a path to healthier aging? What the latest research shows | Bodyworks – The Oklahoman

August 8, 2025
MBU showcases student work at Occupational Therapy Technology Fair – WHSV

Discover the Most Innovative Student Projects at the Occupational Therapy Technology Fair

August 8, 2025
Official | Evann Guessand completes €35m Aston Villa move – Yahoo Sports

Official | Evann Guessand completes €35m Aston Villa move – Yahoo Sports

August 8, 2025
Trailer: Netflix Animation Welcomes Viewers to the Whimsical World of Dr. Seuss! – Animation Magazine

Trailer Unveils the Whimsical World of Dr. Seuss in Netflix Animation!

August 8, 2025
Spending on AI data centers is so massive that it’s taken a bigger chunk of GDP growth than shopping—and it could crash the American economy – Fortune

Spending on AI data centers is so massive that it’s taken a bigger chunk of GDP growth than shopping—and it could crash the American economy – Fortune

August 8, 2025
SPC Health Programs Showcase: Featuring Nursing, Radiography, and Surgical Services Degrees – St. Petersburg College

Explore Exciting Career Paths in Nursing, Radiography, and Surgical Services at SPC Health Programs Showcase

August 8, 2025
Top Trump officials discussed Epstein at White House meeting Wednesday night – CNN

Top Trump officials discussed Epstein at White House meeting Wednesday night – CNN

August 8, 2025

Categories

Archives

August 2025
MTWTFSS
 123
45678910
11121314151617
18192021222324
25262728293031
« Jul    
Earth-News.info

The Earth News is an independent English-language daily published Website from all around the World News

Browse by Category

  • Business (20,132)
  • Ecology (760)
  • Economy (783)
  • Entertainment (21,659)
  • General (16,347)
  • Health (9,822)
  • Lifestyle (793)
  • News (22,149)
  • People (784)
  • Politics (792)
  • Science (15,996)
  • Sports (21,280)
  • Technology (15,763)
  • World (765)

Recent News

Icing‐related injuries in polar bears (Ursus maritimus) at high latitudes – Laidre – 2024 – Ecology – ESA Journals

Frozen Peril: The Devastating Impact of Icing Injuries on Polar Bears in the High Arctic

August 8, 2025
Carnegie Science Center launching new name in September – CBS News

Carnegie Science Center Unveils Exciting New Name This September

August 8, 2025
  • About
  • Advertise
  • Privacy & Policy
  • Contact

© 2023 earth-news.info

No Result
View All Result

© 2023 earth-news.info

No Result
View All Result

© 2023 earth-news.info

Go to mobile version