VMware Releases Security Update for ESXi, vCenter Server, and Cloud Foundation
Security update addresses two vulnerabilities in VMware products
Summary
Security update addresses two vulnerabilities in VMware products
Affected platforms
The following platforms are known to be affected:
Threat details
Introduction
VMware have released security updates to address two security vulnerabilities within vCenter and VMWare EXSi. VMware vCenter Server contains a high severity vulnerability known as CVE-2022-31680 within the Platform Services Controller (PSC), which could lead to an attacker executing arbitrary code. CVE-2022-31680 only impacts vCenter Server version 6.5 with an external PSC. VMware have also released a security update for ESXi to address a low severity null-pointer dereference vulnerability known as CVE-2022-31681, which could allow an attacker to create a denial-of-service attack.
A remote, authenticated attacker could exploit these vulnerabilities to take control of an affected system.
Remediation advice
Affected organisations are encouraged to review VMware Security Advisory VMSA-2022-0025 and apply any relevant updates or workarounds.
Definitive source of threat updates
CVE Vulnerabilities
Last edited: 14 October 2022 9:50 am