A Denial of Service vulnerability threatens the availability of virtual Domain Controllers on VMware ESXi (VMSA-2024-0011, Important, CVE-2024-22273)

This week, Broadcom VMware released an update that addresses a vulnerability in ESXi. This vulnerability could be abused to negatively impact the availability of virtual Domain Controllers running on ESXi hosts. Note:  The vulnerability exists in VMware Cloud Foundation, too. The vulnerability was responsibly disclosed to Broadcom VMware.   About the DoS vulnerability The vulnerability … Continue reading "A Denial of Service vulnerability threatens the availability of virtual Domain Controllers on VMware ESXi (VMSA-2024-0011, Important, CVE-2024-22273)"

VMware's Enhanced Authentication Plug-in is deprecated and critically vulnerable – Remove it now (VMSA-2024-0003)

Two critical vulnerabilities in the optional Enhanced Authentication Plug-in require the immediate removal of this software from admin workstations and management servers.   About VMware's Enhanced Authentication Plug-in VMware's Enhanced Authentication Plug-in (EAP) is an optional piece of software that can be downloaded from VMware's download center and can be installed om admin workstations and … Continue reading "VMware's Enhanced Authentication Plug-in is deprecated and critically vulnerable – Remove it now (VMSA-2024-0003)"

VMSA-2022-0030 updates for VMware ESXi and vCenter Server address four security vulnerabilities (CVE-2022-31696 – CVE-2022-31699)

Yesterday, VMware released updates that addresses four vulnerabilities (CVE-2022-31696, CVE-2022-31697, CVE-2022-31698 and CVE-2022-31699). These vulnerabilities can be used to compromise virtual Domain Controllers running on ESXi. Note: The vulnerabilities exist in VMware Cloud Foundation, too.   About the vulnerabilities VMware addressed these four vulnerabilities: VMware ESXi memory corruption vulnerability (CVE-2022-31696) The first vulnerability is a … Continue reading "VMSA-2022-0030 updates for VMware ESXi and vCenter Server address four security vulnerabilities (CVE-2022-31696 – CVE-2022-31699)"

Veeam Backup & Replication v11a supports VMware vSphere 8.0

Hot on the heels of VMware Explore Europe, Veeam announced its support for VMware vSphere 8.0.   About VMware vSphere 8.0 vSphere is VMware’s advanced server virtualization solution, consisting of ESXi (the core virtualization product that is installed on host machines – a type 1 hypervisor) and vCenter Server (the solution to manage multiple ESXi hosts … Continue reading "Veeam Backup & Replication v11a supports VMware vSphere 8.0"

Eight Tips and Tricks for Backing up and Restoring virtual Domain Controllers with Altaro VM Backup v8

As Active Directory, its Domain Controllers and their inner workings were originally designed in the late 90s, some of the technologies and processes can be somewhat incompatible with technologies and ways of work that were introduced since. I haven’t stumbled upon physical Domain Controllers in a while, so I guess I can conclude that Virtual … Continue reading "Eight Tips and Tricks for Backing up and Restoring virtual Domain Controllers with Altaro VM Backup v8"

VMware finally addresses an important privilege escalation vulnerability in vCenter Server (VMSA-2021-0025)

This week, VMware released an update that finally addresses a vulnerability in vCenter Server. Since November 2021, this vulnerability could be used to compromise vCenter Server installations and the ESXi host they manage. Note:  The vulnerability exists in VMware Cloud Foundation, too.   About vCenter Server VMware vCenter Server, formerly known as VirtualCenter, is the … Continue reading "VMware finally addresses an important privilege escalation vulnerability in vCenter Server (VMSA-2021-0025)"

VMware ESXi 7.0 Update 3c’s cURL version is vulnerable

On January 27th, 2022, VMware released vSphere 7.0 Update 3c. While this much anticipated update to ESXi 7.0 Update 3 addresses a wide range of critical issues, it also – unfortunately – leaves a gap. EARLIER WITH VSPHERE 7 UPDATE 3… In November 2021, VMware took the unprecedented step to retract the ESXi 7 Update … Continue reading "VMware ESXi 7.0 Update 3c’s cURL version is vulnerable"

VMware vSphere 7 Update 3c is now available, accompanied by vCenter Server 7 Update 3c with Log4J fixes

For all virtualization admins, running VMware vSphere, a new stable release of vSphere 7 Update 3 is now available. Additionally, the vCenter Server that is part of this release addresses the Apache Log4j critical security vulnerabilities found in this product. Earlier with vSphere 7 Update 3… In November 2021, VMware took the unprecedented step to … Continue reading "VMware vSphere 7 Update 3c is now available, accompanied by vCenter Server 7 Update 3c with Log4J fixes"

VMSA-2021-0027 updates for VMware vCenter Server 6.5 and 6.7 address two vSphere Web Client vulnerabilities (CVE-2021-21980 and CVE-2021-22049)

Earlier this week, VMware released an update that addresses an arbitrary file read vulnerability in the vSphere Web Client (CVE-2021-21980) and an SSRF vulnerability in the vSphere Web Client (CVE-2021-22049). These two vulnerabilities can be used to compromise virtual Domain Controllers running on VMware vSphere ESXi 6.5 and vSphere ESXi 6.7. About the vulnerabilities arbitrary … Continue reading "VMSA-2021-0027 updates for VMware vCenter Server 6.5 and 6.7 address two vSphere Web Client vulnerabilities (CVE-2021-21980 and CVE-2021-22049)"