Exploitation reported for critical vulnerabilities CVE-2024-38812 and CVE-2024-38813
Summary
Exploitation reported for critical vulnerabilities CVE-2024-38812 and CVE-2024-38813
Affected platforms
The following platforms are known to be affected:
Threat details
Introduction
Broadcom released security updates in Sept 2024 to remediate against CVE-2024-38812 and CVE-2024-38813, vulnerabilities that if exploited could lead to remote code execution and privilege escalation.
These vulnerabilities were not fully remediated by the security updates, and Broadcom reissued the security updates in Oct 2024. The revised advisory included updated software packages to address security and functional issues reported after the original disclosure.
Broadcom has updated their advisory again to report that these vulnerabilities are now being exploited in the wild.
Vulnerability details
Remediation advice
Affected organisations must review Broadcom's VMware advisory VMSA-2024-0019 and VMSA-2024-0019: Questions & Answers and apply the relevant updates.
More information about applying async patches/individual product updates to VMware Cloud Foundation environments using Async Patch Tool (AP Tool) is available in Article ID: 344935.
Definitive source of threat updates
CVE Vulnerabilities
Last edited: 19 November 2024 2:35 pm