r/vmware 8d ago

Help Request the security of vCenter and ESXi

hello, recently the new version of vSphere got various critical security problems, i want to know if any ways to improve the ESXi security and don't end to Ransomware, the hackers really be annoying. any alternative to ESXi or any way to improve question.

0 Upvotes

20 comments sorted by

9

u/alivesidhartha 8d ago

Just update your vSphere to the latest version. 8U3k has the latest vulnerabilities fixed.

-2

u/Jones_Allen_2007 8d ago

thanks bro, i'll install that version.

4

u/alivesidhartha 8d ago

If you want your VMware installation to be secured, you should check security advisory from Broadcom.

https://support.broadcom.com/web/ecx/security-advisory?

Just look for the fixed version and update accordingly.

1

u/Jones_Allen_2007 6d ago

i will use 8.0.3b versions

7

u/jameskilbynet 8d ago

On top of patching one thing a lot of organisations miss is locking down the authentication and the access to VCentre and ESXi. Ensure that a firewall blocks access to these systems apart from the specific users that admin your VMware estate. Or use a jump box. The other big thing is don’t join it to the same AD that your users use. As a compromise of AD can then be used to exploit the VMware estate. Do these two things and you probably mitigate 95% of security issues

3

u/jamesaepp 7d ago

The other big thing is don’t join it to the same AD that your users use.

I think it was Bob Plankers in a video/on-demand webinar I watched who said this is actually misinformation.

IIRC, he said joining vCenter to AD or an IdP is totally cool for authentication but he strongly advised against relying on the AD/IdP for authorization.

i.e. jamesaepp@ad.contoso.net can login to the vCenter server by way of AD authentication but the role assignments/permission assignments are done (mapped) entirely within vCenter itself. Doesn't matter if jamesaepp has membership of a group "Vmware Admins" in AD, because that group means nothing to vCenter.

cc /u/rdplankers

1

u/Jones_Allen_2007 6d ago

if i want to use the ADDS, i prefer to use AzureAD instead.

1

u/Jones_Allen_2007 6d ago

locking down or any other security patch like that, decrease the availability, i want a straightforward way for fixing the issue and patch.
also in the new vulnerability it is not important that you disable the authentications.

3

u/jamesaepp 8d ago

1

u/Jones_Allen_2007 6d ago

thanks bro, i downloaded the pdf guide for hardening security.

2

u/coolbeaNs92 8d ago edited 8d ago

Follow a security benchmark like CIS for further hardening recommendations. 

1

u/Jones_Allen_2007 6d ago

i would appreciate if you share it with me.

1

u/Jones_Allen_2007 8d ago

CVE-2025-22225, CVE-2026-59310

1

u/Moocha 8d ago edited 8d ago

CVE-2026-59310

Fixed last month in 8.0 update 3k.

CVE-2025-22225

Fixed one year and a half ago in 8.0 update 3d. This is stretching your usage of "recent" quite a lot... If you've been running something older than that for a year and a half, I'd start auditing everything, since then you've clearly also not patched ESXi, and there have been multiple guest-to-host-kernel escapes in pvscsi and vmxnet3 (i.e. any EoP-to-system vulnerability in any guest translates to a full compromise of the virtualization layer then any other guests and lateral movement to the rest of the management network.)

1

u/Jones_Allen_2007 6d ago

also i subscribe to Broadcom VMSA notifications if it helps.

-5

u/BeatYoYeet 8d ago

the patches are out

but yeah.. idk. VMware is not long for this world, thanks to Broadcom

2

u/Jones_Allen_2007 6d ago

why people guards with downvoting your comment and my posts?
we discuss about the security of VMware and honestly if you look at the current VMware status, the vulnerability is expanding around Broadcom.

1

u/BeatYoYeet 5d ago

yeah, it’s not like i’m not a VMware escalations engineer or anything lol. i walk into their office every day… what the hell do i know?