Attackers Scan For Vulnerable VMware Servers After PoC Exploit Release

Attackers Scan For Vulnerable VMware Servers After PoC Exploit Release

After security researchers have developed and published proof-of-concept (PoC) exploit code targeting a critical vCenter remote code execution (RCE) vulnerability, attackers are now actively scanning for vulnerable Internet-exposed VMware servers.

The scanning activity was spotted by threat intelligence company Bad Packets just one day after VMware patched the critical vulnerability

Thousands of unpatched vCenter servers are still reachable over the Internet, according to information provided by BinaryEdge (over 14,000 exposed servers) and Shodan (over 6,700).

Mikhail Klyuchnikov of Positive Technologies found the bug (CVE-2021-21972) during the fall of 2020 and reported it privately to VMware in October 2020.

Positive Technologies delayed releasing all the technical details to a later date to give companies enough time to patch their vCenter servers or block public access to them.

Also Read: A Look at the Risk Assessment Form Singapore Government Requires

However, they decided to publish yesterday after at least two PoC exploits for the unauthorized RCE bug were released and hackers started mass scanning for unpatched servers.

Critical RCE with public PoC exploits

Successful exploitation of this security bug allows attackers to take over an organization’s entire network, given that VMware vCenter servers are used by IT admins to manage VMware solutions deployed across their enterprise environments via a single console.

“The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin,” VMware explained.

“A malicious actor with network access to port 443 may exploit this issue to execute commands with unrestricted privileges on the underlying operating system that hosts vCenter Server.”

As the company further added, the impacted vCenter Server plugin for vRealize Operations (vROps) is present in all default installations.

VMware issued a security update this week, on Tuesday, and rated the security vulnerability with an almost maximum severity rating of 9.8 out of 10.

VMware also provides a workaround designed to remove the possibility of exploitation for admins who cannot immediately update.

Detailed steps on implementing the workaround can be found in VMware’s KB82374 support document.

To highlight the importance of patching vulnerable vCenter servers exposed and avoiding exposing them over the Internet, VMware vulnerabilities have been exploited in the past in ransomware attacks targeting enterprise networks.

Also Read: CCTV Law Singapore Edition: Know Your Rights and Responsibilities

Multiple ransomware gangs, including RansomExx, Babuk Locker, and Darkside, have used VMWare ESXi pre-auth RCE exploits to encrypt ESXi instances’ virtual hard disks used as centralized enterprise storage space, as ZDNet reported last year.

Privacy Ninja

Recent Posts

Role of Enhanced Access Controls in Safeguarding Personal Data in Telecommunications

Role of Enhanced Access Controls in Safeguarding Personal Data in Telecommunications that every Organisation in…

2 weeks ago

Role of Effective Incident Response Procedures in Strengthening Data Security

Effective Incident Response Procedures in Strengthening Data Security that every Organisation in Singapore should know…

2 weeks ago

Strengthening Your Cyber Defenses: The Crucial Role of Regular Vulnerability Scanning

Crucial Role of Regular Vulnerability Scanning that every Organisation in Singapore should know. Strengthening Your…

2 weeks ago

Enhancing Data Security with Multi-Factor Authentication

Enhancing Data Security with Multi-Factor Authentication that every Organisation in Singapore should know. Enhancing Data…

3 weeks ago

A Strong Password Policy: Your Organization’s First Line of Defense Against Data Breaches

Strong Password Policy as a first line of defense against data breaches for Organisations in…

3 weeks ago

Enhancing Website Security: The Importance of Efficient Access Controls

Importance of Efficient Access Controls that every Organisation in Singapore should take note of. Enhancing…

4 weeks ago