VMware vCenter contains an improper check for dropped privileges vulnerability. This vulnerability could allow an attacker with network access to the vCenter Server to escalate privileges to root by sending a specially crafted packet. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
VMware vCenter Server contains a heap-based buffer overflow vulnerability in the implementation of the DCERPC protocol. This vulnerability could allow an attacker with network access to the vCenter Server to execute remote code by sending a specially crafted packet. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
VMware vCenter Server contains an incorrect default file permissions vulnerability that allows a remote, privileged attacker to gain access to sensitive information. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
VMware vCenter Server contains an out-of-bounds write vulnerability in the implementation of the DCERPC protocol that allows an attacker to conduct remote code execution. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Rhttproxy as used in vCenter Server contains a vulnerability due to improper implementation of URI normalization. Required action: Apply updates per vendor instructions.
VMware vCenter Server contains a file upload vulnerability in the Analytics service that allows a user with network access to port 443 to execute code. Required action: Apply updates per vendor instructions.
VMware vCenter Server contains an information disclosure vulnerability in the VMware Directory Service (vmdir) when the Platform Services Controller (PSC) does not correctly implement access controls. Successful exploitation allows an attacker with network access to port 389 to extract sensitive information. Required action: Apply updates per vendor instructions.
VMware vCenter Server vSphere Client contains a remote code execution vulnerability in a vCenter Server plugin which allows an attacker with network access to port 443 to execute commands with unrestricted privileges on the underlying operating system. Required action: Apply updates per vendor instructions.
VMware vSphere Client contains an improper input validation vulnerability in the Virtual SAN Health Check plug-in, which is enabled by default in vCenter Server, which allows for remote code execution. Required action: Apply updates per vendor instructions.