Advisory Notification - VMware Vulnerabilities VMSA-2024-0013.1
Advisory Notification: VMware Vulnerabilities (VMSA-2024-0013.1) The severity of the advisory is categorized as moderate, with the affected products encompassing VMware ESXi, vCenter Server, and VMware Cloud Foundation. The identified issues consist of an authentication bypass vulnerability in ESXi's Active Directory Integration (CVE-2024-37085), an out-of-bounds read vulnerability in ESXi (CVE-2024-37086), and a denial-of-service vulnerability in vCenter Server (CVE-2024-37087). The ESXi authentication bypass vulnerability (CVE-2024-37085) carries a maximum CVSSv3 base score of 6.8. This vulnerability can be exploited by a malicious actor possessing adequate Active Directory permissions, thereby granting full access to an ESXi host. The ESXi out-of-bounds read vulnerability (CVE-2024-37086) also has a maximum CVSSv3 base score of 6.8. This vulnerability can be triggered by a malicious actor with local administrative privileges on a virtual machine, resulting in a denial-of-...
