VMware warns admins of public exploit for vRealize RCE flaw 

PoC exploit code is now available for an authentication bypass flaw in vRealize Log Insight

clock • 2 min read
VMware warns admins of public exploit for vRealize RCE flaw 
Image:

VMware warns admins of public exploit for vRealize RCE flaw 

VMware has alerted its users to a significant security threat to its vRealize cloud management solution, now known as VMware Aria Operations for Logs.

Identified as CVE-2023-34051 in a recent advisory, the high-severity remote code execution (RCE) flaw (CVSS score 8.1) can potentially allow unauthorised individuals to execute code with root privi...

To continue reading this article...

Join Computing

  • Unlimited access to real-time news, analysis and opinion from the technology industry
  • Receive important and breaking news in our daily newsletter
  • Be the first to hear about our events and awards programmes
  • Join live member only interviews with IT leaders at the ‘IT Lounge’; your chance to ask your burning tech questions and have them answered
  • Access to the Computing Delta hub providing market intelligence and research
  • Receive our members-only newsletter with exclusive opinion pieces from senior IT Leaders

Join now

 

Already a Computing member?

Login

You may also like
Ransomware operators exploit simple flaw in VMware ESXi to launch attacks

Threats and Risks

Now-patched bug allowed attackers to circumvent Microsoft AD authentication checks

clock 30 July 2024 • 2 min read
Nutanix: We're staying true to open source

Open Source

HCI vendor promises to support CNCF projects 'across all environments'

clock 23 May 2024 • 4 min read
University IT chief: 'We count ourselves lucky we're not on VMware'

Business Software

Nutanix .Next event saw customers looking for alternatives

clock 22 May 2024 • 5 min read

Sign up to our newsletter

The best news, stories, features and photos from the day in one perfectly formed email.

More on Threats and Risks

UK and allies reveal methodology of Russian GRU threat actor Unit 29155

UK and allies reveal methodology of Russian GRU threat actor Unit 29155

Group has targeted organisations including governments and critical infrastructure providers for espionage purposes

John Leonard
clock 06 September 2024 • 2 min read
Veeam patches critical flaws, urges users to update

Veeam patches critical flaws, urges users to update

The most concerning glitch affects VBR software

clock 06 September 2024 • 2 min read
Researchers ID security risks in GenAI development platforms

Researchers ID security risks in GenAI development platforms

Exposes sensitive company data

clock 29 August 2024 • 2 min read