VMware pushes admins to uninstall vulnerable, deprecated vSphere plugin (CVE-2024-22245, CVE-2024-22250)

VMware Enhanced Authentication Plug-in (EAP), a plugin for VMware vSphere, has two vulnerabilities (CVE-2024-22245, CVE-2024-22250) that could be exploited by attackers to mount authentication relay and session hijack attacks. The vulnerabilities haven… Continue reading VMware pushes admins to uninstall vulnerable, deprecated vSphere plugin (CVE-2024-22245, CVE-2024-22250)

Broadcom and Google Unveil New VMware License Portability Plan for Businesses

Broadcom and Google have announced a new license portability plan that will allow enterprise customers to run VMware workloads on Google Cloud. Broadcom is also actively advocating for the benefits of the changes to its VMware products among partners and customers. In the new license portability scheme, customers who purchased VMware Cloud Foundation software from…

The post Broadcom and Google Unveil New VMware License Portability Plan for Businesses appeared first on Petri IT Knowledgebase.

Continue reading Broadcom and Google Unveil New VMware License Portability Plan for Businesses

Chinese Spies Exploited VMware vCenter Server Vulnerability Since 2021

CVE-2023-34048, a vCenter Server vulnerability patched in October 2023, had been exploited as zero-day for a year and a half.
The post Chinese Spies Exploited VMware vCenter Server Vulnerability Since 2021 appeared first on SecurityWeek.
Continue reading Chinese Spies Exploited VMware vCenter Server Vulnerability Since 2021

VMware: Plug critical Aria Automation hole immediately! (CVE-2023-34063)

A critical vulnerability (CVE-2023-34063) affecting VMware Aria Automation and VMware Cloud Foundation can be exploited by attackers to gain access to remote organizations and workflows, VMware has warned. The company is not aware of any “in the … Continue reading VMware: Plug critical Aria Automation hole immediately! (CVE-2023-34063)