Database/Control plane, storage & DevOps
VMware vCenter (Syslog server directory traversal to RCE): Directory traversal in the vCenter syslog server letting
Impact
Directory traversal in the vCenter syslog server letting an unauthenticated network attacker execute arbitrary code on vCenter. Chained with the authentication bypass in the same advisory, this is the full remote-takeover pair - and it is being exploited in the wild.
Who can reach it
Network access to vCenter. Unauthenticated.
What to do
Apply the Broadcom fix immediately. vCenter patch and restart. Assume compromise on any vCenter that was network-exposed and unpatched during the exploitation window; rotate vCenter and ESXi credentials afterwards.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.