vCenter Java JMX/RMI Remote Code Execution

Discussion in 'News Aggregator' started by Packet Storm, 3 Oct 2015.

  1. Packet Storm

    Packet Storm Guest

    VMware vCenter Server provides a centralized platform for managing your VMware vSphere environments so you can automate and deliver a virtual infrastructure. VMware vCenter was found to bind an unauthenticated JMX/RMI service to the network stack. An attacker with access can abuse the configuration to achieve remote code execution, providing SYSTEM level access to the server.

    Continue reading...
     

Share This Page

Loading...