Our Cybersecurity SOC partner has identified five vulnerabilities affecting VMware vCenter Server and ESX, including two critical, unauthenticated vulnerabilities in vCenter and a critical guest-to-host escape affecting the VMXNET3 virtual network adapter. Patches are available for all affected versions.
vCenter and ESX are administrative platforms that provide broad control across enterprise virtual environments, making them attractive targets for threat actors. An attacker who successfully exploits the authentication bypass or directory traversal vulnerabilities could gain unauthorized access to vCenter and execute code remotely, without needing valid credentials. Once compromised, these systems can be abused to expand access, move laterally, or execute malicious actions using legitimate administrative functionality. The VMXNET3 vulnerability could allow a user with local administrative privileges inside a VM to break out and execute code directly on the underlying host.
As of publication, there is no publicly reported evidence of active exploitation for any of the five vulnerabilities. However, given the severity (two rated CVSS 9.8) and the unauthenticated nature of the primary vCenter flaws, organizations should treat this as a high-priority patching item.
Our Cybersecurity SOC partner focuses on identifying the post-compromise behaviors commonly associated with abuse of trusted management platforms like vCenter and ESX. Their team continues to monitor for signs of exploitation and will provide updates as new information becomes available.
If you have any questions about this advisory or would like help verifying your patch status, please contact your Black Diamond Solutions account team.