Published on: 26 October 2023
VMware has published a security advisory to address multiple vulnerabilities in VMware products. The details of security updates can be found at:
https://www.vmware.com/security/advisories/VMSA-2023-0023.html
Reports indicate that a vulnerability (CVE-2023-34048) in VMware vCenter Server is at high risk of exploitation. A malicious actor with network access to vulnerable systems may exploit the vulnerability to execute arbitrary code. System administrators are advised to take immediate action to patch your affected systems to mitigate the elevated risk of cyber attacks.
Depending on the vulnerabilities being exploited, a successful exploitation of the vulnerabilities could lead to remote code execution or information disclosure on the affected system.
Patches for affected products are available. System administrators of affected systems should follow the recommendations provided by the product vendor and take immediate actions to mitigate the risk. As a security best practice, it is advised not to expose VMware vCenter servers to the Internet if not necessary.