Header image overlay

Security Alerts

Our support will regularly inform you of important events here.

Would you like to be notified by e-mail in case of future Security Alerts? Then sign up here in!

VMware has fixed 2 critical vulnerabilities (CVE-2024-37079 + CVE-2024-37080) impacting vCenter Server versions 7.0 & 8.0, as well as Cloud Foundation versions 4.x & 5.x.

A hacker with network access to the vCenter Server could exploit this vulnerability by sending a specially crafted network packet that might lead to execution of external code. For now, Broadcom has not received any reports of abuse of this vulnerability.

Both CVEs are 'heap-overflow' vulnerabilities in the implementation of the DCE/RPC protocol. They have high risk scores because the attacks can be performed remotely without any user interaction.

Take action

So upgrading/patching is a must. Temporarily, you could also restrict access via advanced firewall configurations to minimise possible attack attempts.

Customers who use our Managed Services enjoy are safe. They have since been patched or are being patched by appointment.
The impact of the operation/upgrade is that VCenter needs to be restarted, which (only) VCenter unreachable for up to one hour.

Feel free to contact us to fix this problem for you. You can do this by mail at support@vanroey.be or count: 014 470 600. You can also have a create a ticket.

Fortinet has released important security updates for FortiOS firmware versions 6.0, 6.2, 6.4, 7.0, 7.2, 7.4 and 7.6.
An out-of-bounds write vulnerability is thus shielded. You can find more info on this vulnerability at this link.

Take action

The above vulnerability is very critical (CVE score = 9.8) and therefore immediate action is required!

We noticed this remarkable amount of updates being made available yesterday and have proactively anticipated this. So if you have a service contract, you have already been contacted and/or the necessary patches are being rolled out. This further ensures the security of your IT environment.

Don't have a service contract and would like to call on our experts to update your firewall(s)? Then contact us via the info below.

VMware has addressed vulnerabilities hidden in vCenter Server. These vulnerabilities were announced under CVE-2023-34048, CVE-2023-34056. A similar vulnerability was also fixed earlier this year.

A malicious person with network access to vCenter Server could potentially exploit this problem to execute arbitrary code on the underlying operating system.

Take action

The severity of this vulnerability is high (CVE score = 9.8), which means action is required. We recommend that you upgrade vCenter to version 7.0U3o or 8.0U1d. This upgrade will not cause any disruption to your environment and can be performed during business hours.

Given the urgency of the situation, we are implementing these upgrades proactively at our Managed Services clients.

Do you have questions about this or do you, as a non-Managed Services customer, still want support? Please do not hesitate to contact us: support@vanroey.be.

Citrix recently a security bulletin released regarding NetScaler ADC and NetScaler Gateway. This includes multiple vulnerabilities with identifiers CVE-2023-3466, CVE-2023-3467, CVE-2023-3519.

A malicious person could potentially exploit this problem remotely to execute arbitrary code.

Take action

The severity of this vulnerability is high (CVE score = 9.8), which means action is required. We recommend that you upgrade Netscaler to the latest version according to Citrix recommendations.

Given the urgency of the situation, we contacted  proactive our Managed Services clients who are using Citrix NetScaler to schedule the update.

Do you have questions about this or do you, as a non-Managed Services customer, still want support? Please do not hesitate to contact us: support@vanroey.be.

VMware recently addressed multiple memory corruption vulnerabilities in vCenter Server that can be exploited to execute external code. These vulnerabilities, designated CVE-2023-20892 to CVE-2023-20896, are in the software implementation of the DCERPC protocol.

A malicious person with network access to vCenter Server could potentially exploit this problem to execute arbitrary code on the underlying operating system hosting vCenter Server.

Take action

The severity of this vulnerability is high (CVE score = 5.9-8.1), which means action is required. We recommend that you upgrade vCenter to version 7.0U3m or 8.0 U1b, released on 22 June 2023. This upgrade will not cause any disruption to your environment and can be performed during business hours.

Given the urgency of the situation, we are implementing these upgrades proactively at our Managed Services clients.

Do you have questions about this or do you, as a non-Managed Services customer, still want support? Please do not hesitate to contact us: support@vanroey.be.

Fortinet has released important security updates for FortiOS firmware versions 6.0, 6.2, 6.4, 7.0 and 7.2. An official communication regarding a possible leak is not yet available, but it is suggested that it is a critical SSL-VPN RCE vulnerability that this update fixes.

Take action

The above vulnerability is very critical (CVE score = 9.2) and therefore immediate action is required! Customers with a service contract whose environment we can remotely access will be patched after business hours (7pm).

Don't have a service contract and would like to call on our experts to update your firewall(s)? Then contact us via the info below.

Our own Inspiration Centre in Geel provides the perfect setting to welcome you this autumn and take you into the latest trends within the IT world.

Attention: limited number of places!