Close Menu
Edu Expertise Hub
    Facebook X (Twitter) Instagram
    Sunday, June 15
    • About us
    • Contact
    • Submit Coupon
    Facebook X (Twitter) Instagram YouTube
    Edu Expertise Hub
    • Home
    • Udemy Coupons
    • Best Online Courses and Software Tools
      • Business & Investment
      • Computers & Internet
      • eBusiness and eMarketing
    • Reviews
    • Jobs
    • Latest News
    • Blog
    • Videos
    Edu Expertise Hub
    Home » Latest News » Hacking contest exposes VMware security
    Latest News

    Hacking contest exposes VMware security

    TeamBy TeamMay 21, 2025No Comments3 Mins Read10 Views
    Facebook Twitter Pinterest LinkedIn Telegram Tumblr Email
    VMware vSAN Max: What you need to know
    Share
    Facebook Twitter LinkedIn Pinterest Email


    The cyber security team at Broadcom has acknowledged that during the Pwn2Own hacking contest in Berlin in March, there were three successful attacks on the VMware hypervisor. 

    On March 16, Nguyen Hoang Thach, a security researcher from Star Labs, successfully exploited VMware ESXi. “This is the first time VMware ESXi was exploited in the Pwn2Own hacking event,” Praveen Singh and Monty Ijzerman, from the product security and incident response team in the VMware Cloud Foundation division of Broadcom, wrote on the company’s website. 

    This is something that has not been achieved before, according to a LinkedIn post by Bob Carver, CEO of Cybersecurity Boardroom.

    “This was the first time in Pwn2Own’s history, stretching back to 2007, that the hypervisor has been successfully exploited,” he wrote, adding that the hacker was able to deploy a single integer overflow exploit.

    Singh and Ijzerman also noted that on 17 March, Corentin Bayet, chief technology officer of Reverse Tactics, successfully exploited ESXi by chaining two vulnerabilities. According to Singh and Ijzerman, one of the vulnerabilities used in the exploit was already known.

    The third successful attack, also on 17 March, was run by Thomas Bouzerar and Etienne Helluy-Lafont, security experts from Synacktiv, who managed to successfully exploit the VMware workstation.

    Singh and Ijzerman said the team at Broadcom were actively working on the remediation. “We plan to publish a VMware Security Advisory to provide information on updates for the affected products,” they said.

    While Broadcom has so far committed to providing patches for zero-day exploits, its current strategy to move customers onto VMware Cloud Foundation subscription bundles may leave some VMware users with gaps in their security, especially if their support contract is up for renewal.

    As Computer Weekly reported earlier this month, Broadcom informed customers it would no longer renew support contracts for VMware products purchased on a perpetual licence basis and that support would only continue for those that moved to a VMware subscription.

    On 12 May, Broadcom issued a critical security advisory, CVE-2025-22249, which affects the Aria toolset. The Cybersecurity Centre for Belgium said that given the vulnerability requires user interaction, it could be exploited through a phishing attack if a VMware admin clicked on a malicious URL link.

    “If the user is logged in to their VMware Aria Automation account, the threat actor could gain full control of their account and perform any actions the user has the rights to perform. The vulnerability has a severe impact to the confidentiality and low impact to the integrity of the affected systems,” it warned, urging VMware users to “patch immediately”.

    Broadcom has issued patches for VMware Aria Automation 8.18.x and version 5.x and 4.x of VMware Cloud Foundation, but it has not provided any workarounds, which means those users running an older version of the tool remain at risk.

    There are a number of reports that many VMware customers have been sent cease-and-desist emails from Broadcom regarding their perpetual VMware licenses, which demand removal of patches and bug fixes that they may have installed.

    While details of the successful exploits of the VMware hypervisor have yet to be published, the patches are not yet available, and questions remain as to how widely these will be distributed.

    This post is exclusively published on eduexpertisehub.com

    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Team

      Related Posts

      Ignite Reading Again Approved as 1:1 High-Dosage Early Literacy Tutoring Provider in Massachusetts

      June 15, 2025

      Fortifying retail: how UK brands can defend against cyber breaches

      June 15, 2025

      I’ve Taught Gen Z for Almost a Decade. I’m Split on the So-Called Gen Z ‘Split’

      June 14, 2025

      Counslr Launches in Texas to Increase Access to Mental Health Support for Staff and Students

      June 14, 2025

      CIOs baffled by ‘buzzwords, hype and confusion’ around AI

      June 13, 2025

      Schools Can’t Find Teachers. Do States Need More Credential Rules or Fewer?

      June 13, 2025
      Courses and Software Tools

      Extreme Privacy: What It Takes to Disappear

      August 24, 202449 Views

      Modern C++ Programming Cookbook: Master Modern C++ with comprehensive solutions for C++23 and all previous standards

      September 18, 202426 Views

      Meebook E-Reader M7 | 6.8′ Eink Carta Screen | 300PPI Smart Light | Android 11 | Ouad Core Processor | Out Speaker | Support Google Play Store | 3GB+32GB Storage | Micro-SD Slot | Gray

      August 19, 202422 Views

      HR from the Outside In: Six Competencies for the Future of Human Resources

      May 20, 202517 Views

      Coders at Work: Reflections on the Craft of Programming

      April 19, 202516 Views
      Reviews

      Arduino Bluetooth: Step BY Step Guide | Udemy Coupons 2025

      June 15, 2025

      Creative Director

      June 15, 2025

      OAuth 2 in Action

      June 15, 2025

      Boss Life: Surviving My Own Small Business

      June 15, 2025

      Cyberjutsu: Cybersecurity for the Modern Ninja

      June 15, 2025
      Stay In Touch
      • Facebook
      • YouTube
      • TikTok
      • WhatsApp
      • Twitter
      • Instagram
      Latest News

      Ignite Reading Again Approved as 1:1 High-Dosage Early Literacy Tutoring Provider in Massachusetts

      June 15, 2025

      Fortifying retail: how UK brands can defend against cyber breaches

      June 15, 2025

      I’ve Taught Gen Z for Almost a Decade. I’m Split on the So-Called Gen Z ‘Split’

      June 14, 2025

      Counslr Launches in Texas to Increase Access to Mental Health Support for Staff and Students

      June 14, 2025

      CIOs baffled by ‘buzzwords, hype and confusion’ around AI

      June 13, 2025
      Latest Videos

      Digital Marketing Salary In India | Mujhe Kitni Salary Milti Hai?

      June 15, 2025

      Club Career FC Barcelona (2004-2021): Messi played for FC Barcelona

      June 13, 2025

      Get Ahead of the Game with the #1 FREE Cybersecurity Career Launchpad Resource!

      June 12, 2025

      How Hospitality Work Helped My Marketing Career

      June 11, 2025

      Ethical Hacking is an Officially Recognized Career!

      June 10, 2025
      Latest Jobs

      Creative Director

      June 15, 2025

      On-Page SEO Expert

      June 15, 2025

      Sr. Sales Manager

      June 15, 2025

      Data Science Consultant

      June 15, 2025

      Nursing Instructor – FT40

      June 15, 2025
      Legal
      • Home
      • Privacy Policy
      • Cookie Policy
      • Terms and Conditions
      • Disclaimer
      • Affiliate Disclosure
      • Amazon Affiliate Disclaimer
      Latest Udemy Coupons

      Mastering Maxon Cinema 4D 2024: Complete Tutorial Series | Udemy Coupons 2025

      August 22, 202435 Views

      Advanced Program in Human Resources Management | Udemy Coupons 2025

      April 5, 202530 Views

      Diploma in Aviation, Airlines, Air Transportation & Airports | Udemy Coupons 2025

      March 21, 202529 Views

      Python Development & Data Science: Variables and Data Types | Udemy Coupons 2025

      May 24, 202521 Views

      Time Management and Timeboxing in Business, Projects, Agile | Udemy Coupons 2025

      April 2, 202521 Views
      Blog

      Why Feedback Will Help Your Professional Development

      June 14, 2025

      4 Ways To Improve Your LinkedIn Presence

      June 13, 2025

      5 Ways To Develop Your Leadership Skills

      June 12, 2025

      7 Vital Habits Of Successful People

      June 10, 2025

      How To Escape The One-Job Trap In 30 Days

      June 8, 2025
      Facebook X (Twitter) Instagram Pinterest YouTube Dribbble
      © 2025 All rights reserved!

      Type above and press Enter to search. Press Esc to cancel.

      We use cookies on our website to give you the most relevant experience by remembering your preferences and repeat visits. By clicking “Accept”, you consent to the use of ALL the cookies.
      .
      SettingsAccept
      Privacy & Cookies Policy

      Privacy Overview

      This website uses cookies to improve your experience while you navigate through the website. Out of these, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may affect your browsing experience.
      Necessary
      Always Enabled
      Necessary cookies are absolutely essential for the website to function properly. This category only includes cookies that ensures basic functionalities and security features of the website. These cookies do not store any personal information.
      Non-necessary
      Any cookies that may not be particularly necessary for the website to function and is used specifically to collect user personal data via analytics, ads, other embedded contents are termed as non-necessary cookies. It is mandatory to procure user consent prior to running these cookies on your website.
      SAVE & ACCEPT