VMware ESXi – CVE-2021-21974 A new vulnerability was reported by security researchers. This article describes an explosion in the compromises of VMware ESXi hypervisors with over 500 machines hit by ransomware this weekend, with the automated attacks likely exploiting CVE-2021- 21974. VMware initially described CVE-2021-21974 (CVSS 8.8 [HIGH]) in its February 2021 VMSA-2021-0002 advisory as letting a “malicious actor residing within the same network segment as ESXi who has access to port 427 may be able to trigger the heap- overflow issue in OpenSLP service resulting in remote code execution”.
Read more in our report
Freeze – payload creation tool
Freeze is a powerful tool that enables the creation of payloads, which can circumvent EDR security controls and execute shellcode in a stealthy manner. Freeze deploys various techniques to eliminate Userland EDR hooks and execute shellcode in a way that avoids detection by other endpoint monitoring controls.
An associated SOC alert is being developed.
Read more in our report