VMware vCenter Vulnerability Exploited for Persistent Access
TL;DR. Attackers are actively exploiting a critical VMware vCenter Server vulnerability (CVE-2023-34048) to establish persistent remote access to compromised systems. - The flaw is a bypass of a previous patch, allowing command injection via the vCenter Server Appliance Management Interface (VAMI). - Successful exploitation grants root privileges, enabling full control over the affected virtualized environment. - Organizations must apply the latest security updates immediately to protect their critical infrastructure.
- VMware vCenter Server vulnerability CVE-2023-34048 is under active exploitation by threat actors.
- The flaw allows unauthenticated remote command injection through the VAMI.
- Attackers gain root access, enabling persistent control over virtualized environments.
- This vulnerability is a bypass for a previously patched issue, highlighting persistent security challenges.
- Immediate patching of vCenter Server instances is critical to prevent compromise.
Sources
- Attackers Exploit VMware vCenter Vulnerability to Gain Persistent Remote Access — thehackernews.com