VMware patches critical vCenter Server vulnerability

By
Follow google news

Remotely exploitable bug in Adobe-developed messaging system.

Virtualisation giant VMware has issued a patch to address a critical vulnerability in its vCenter Server management software that could be used to execute arbitrary code remotely.

VMware patches critical vCenter Server vulnerability

The vulnerability affects vCenter Server versions 6.0 and 6.5 and was disclosed on 4 April, VMWare said.

It originates in the open source Java-based Flex BlazeDS remoting and messaging protocol, developed by Adobe and now maintained by the Apache Foundation.

BlazeDS utilises Action Message Format version 3 binary messaging files to let Adobe Flash applications communicate with each other and to translate the company's ActionScript coded graphs into data types.

By deserialising untrusted Java objects, attackers could execute any code they wish, VMware said.

According to the company, the issue is present in the vCenter Server Customer Experience Improvement Program (CEIP). Even if customers opt out of the CEIP, the vulnerability remains. 

Markus Wulftange from security vendor Code White discovered the bug. He said the AMF 3 vulnerability could affect other vendors as well, including Adobe, Atlassian, HPE, and SonicWall which also use the Java libraries in question.

Atlassian has acknowledged the flaw, and patched the critical vulnerability in its JIRA Server Workflow Designer plugin in March this year.

Add iTnews as your trusted source

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © iTnews.com.au . All rights reserved.
Tags:

Most Read Articles

Services Australia describes fraud, debt-related machine learning use cases

Services Australia describes fraud, debt-related machine learning use cases

Medibank reveals attack vector and cost of 2022 security breach

Medibank reveals attack vector and cost of 2022 security breach

USB stick opens Windows BitLocker drives in new zero-day

USB stick opens Windows BitLocker drives in new zero-day

'ClickFix' attack tricks users into hacking themselves, ACSC warns

'ClickFix' attack tricks users into hacking themselves, ACSC warns

Log In

  |  Forgot your password?