VMware, a leading cloud computing and virtualization software provider, has disclosed multiple critical vulnerabilities in its Aria Operations product. The most severe flaws could allow attackers to escalate privileges to the root user on affected systems.
The advisory, identified as VMSA-2024-0022, was released on November 26, 2024, and addresses five distinct vulnerabilities:
The two local privilege escalation vulnerabilities (CVE-2024-38830 and CVE-2024-38831) are particularly concerning.
Leveraging 2024 MITRE ATT&CK Results for SME & MSP Cybersecurity Leaders – Attend Free Webinar
They allow malicious actors with local administrative privileges to elevate their access to root users on the appliance running VMware Aria Operations. This could potentially give attackers complete control over the affected systems.
The stored XSS vulnerabilities (CVE-2024-38832, CVE-2024-38833, and CVE-2024-38834) allow attackers with editing access to various components (views, email templates, and cloud provider settings) to inject malicious scripts. These scripts could then be executed when other users access the affected areas of the application.
The vulnerabilities impact VMware Aria Operations versions 8.x up to 8.18.1. Additionally, VMware Cloud Foundation versions 4.x and 5.x, which include VMware Aria Operations, are also affected.
VMware has released patches to address these vulnerabilities. Users are strongly advised to update to VMware Aria Operations version 8.18.2, which resolves all five reported issues. There are no workarounds available, making it crucial for organizations to apply the patches as soon as possible.
VMware has credited several security researchers, including this codec of MoyunSec Vlab, Bing, and members of the Michelin CERT team, with responsibly reporting these vulnerabilities.
Analyze cyber threats with ANYRUN's powerful sandbox. Black Friday Deals : Get up to 3 Free Licenses.
Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…
Hackers are making some phishing pages harder to track by changing the code delivered to…
A cyber incident reportedly forced a British power plant to halt operations for about four…
Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…
TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…
A fake student resume is being used to place a remote-access tool on researchers’ Windows…