Skip to main content

VMware Releases Security Update for ESXi, vCenter Server, and Cloud Foundation

Security update addresses two vulnerabilities in VMware products

Report a cyber attack: call 0300 303 5222 or email [email protected]

Summary

Security update addresses two vulnerabilities in VMware products


Threat details

Introduction

VMware have released security updates to address two security vulnerabilities within vCenter and VMWare EXSi. VMware vCenter Server contains a high severity vulnerability known as CVE-2022-31680 within the Platform Services Controller (PSC), which could lead to an attacker executing arbitrary code.  CVE-2022-31680 only impacts vCenter Server version 6.5 with an external PSC. VMware have also released a security update for ESXi to address a low severity null-pointer dereference vulnerability known as CVE-2022-31681, which could allow an attacker to create a denial-of-service attack. 

 A remote, authenticated attacker could exploit these vulnerabilities to take control of an affected system. 


Remediation advice

Affected organisations are encouraged to review VMware Security Advisory VMSA-2022-0025 and apply any relevant updates or workarounds.



Last edited: 14 October 2022 9:50 am