important · Remote code execution
Patch analysis demonstrates two independent pre-authentication routes into VMware vCenter.
Affects
VMware vCenter Server Appliance, the virtualization-management control plane deployed in vSphere and VMware Cloud Foundation environments.
One route uses a crafted SRP value to authenticate to vmdir as an existing identity without its password. The other uses traversal in syslog fields for arbitrary file write; researchers reached code execution but withheld the final sink. Broadcom has fixed builds, while pre-fix image acceptance and revocation completeness remain unknown.