Multiple vulnerabilities were identified in VMware products, a malicious actor residing within the same network segment as ESXi who has access to port 427 may be able to trigger the heap-overflow issue in OpenSLP service resulting in remote code execution.
The following systems/applications are affected:
- VMware vCenter Server version 7.0, 6.7 and 6.5
- VMware ESXi version 7.0, 6.7 and 6.5.0
VMware have released a security update to address vulnerabilities in VMware vCenter Server and VMware ESX.
For more details, please refer to: https://www.vmware.com/security/advisories/VMSA-2021-0002.html
Matsco Solutions are currently testing the fix to ensure there are no issues with it and will be reaching out to clients running VMware to schedule updates to their environments.