VMware Finds No Evidence of 0-Day in Ongoing ESXiArgs Ransomware Spree

February 7, 2023Rabbi LakshmananEndpoint security / zero-day

VMware ransomware

VMware said on Monday it found no evidence that attackers were exploiting an unknown security flaw, or zero-day, in its software as part of its ongoing ransomware attacks around the world.

Virtualization service providers state that “Most reports indicate that end of general support (EoGS) and/or significantly older products are targeted by known vulnerabilities previously addressed and disclosed in VMware Security Advisories (VMSA). It is said that

The company also recommends users upgrade to the latest supported release of vSphere components to mitigate known issues and disable the OpenSLP service on ESXi.

“In 2021, ESXi 7.0 U2c and ESXi 8.0 GA will start shipping with the service disabled by default,” added VMware.

The announcement follows a two-year-old bug that VMware has patched in February 2021 to exploit unpatched and unprotected devices targeted in a massive ransomware campaign called ESXiArgs. It indicates that VMware ESXi servers worldwide that are not covered are covered.

The vulnerability tracked as CVE-2021-21974 (CVSS score: 8.8) is an OpenSLP heap-based buffer overflow vulnerability that can be exploited by unauthenticated attackers to remotely execute code.

The intrusion appears to have identified a susceptible ESXi server exposed to the Internet on OpenSLP port 427, and the victim paid 2.01 Bitcoins (at the time of writing) to receive the encryption key needed to recover the files. approximately $45,990 in So far, no data exfiltration has been confirmed.

Data from GreyNoise shows that since February 4, 2023, 19 unique IP addresses have attempted to exploit vulnerabilities in ESXi.

Rapid7 researcher Caitlin Condon said, “ESXi customers can urgently update their ESXi installations to fixed versions without waiting for regular patch cycles to make sure their data is backed up. “When possible, do not expose ESXi instances to the internet.”

Did you find this article interesting?Please follow us twitter and LinkedIn to read more exclusive content we post.



Source link

Leave a Reply

Your email address will not be published. Required fields are marked *