Slashdot: VMware Prevents Some Perpetual License Holders From Downloading Patches

Source URL: https://tech.slashdot.org/story/25/07/24/0125217/vmware-prevents-some-perpetual-license-holders-from-downloading-patches?utm_source=rss1.0mainlinkanon&utm_medium=feed
Source: Slashdot
Title: VMware Prevents Some Perpetual License Holders From Downloading Patches

Feedly Summary:

AI Summary and Description: Yes

Summary: The text highlights significant security implications for customers of Broadcom’s VMware business due to limited access to security patches for users with perpetual licenses lacking current support contracts. This impacts their security posture and raises concerns regarding timely patch delivery for critical vulnerabilities.

Detailed Description: The issue at hand involves Broadcom’s VMware customers who possess perpetual licenses but lack current support contracts, severely limiting their ability to access essential security patches.

Key points include:

– **Access to Security Patches**: Customers without an active support contract are currently at a heightened risk of cyberattacks, as they cannot obtain security patches that address vulnerabilities in their VMware products.
– **Business Policies**: Broadcom’s policy requires users to sign up for software subscriptions to renew support contracts, thereby restricting access to security updates for those who do not.
– **Commitment from Leadership**: Despite these challenges, Broadcom CEO Hock Tan has publicly promised free access to zero-day security patches for supported versions of vSphere to mitigate risks associated with using perpetual licenses.
– **Current Limitations**: Users have reported difficulties accessing the needed patches through Broadcom’s support portal, with some facing a wait of up to 90 days for the necessary software fixes.
– **Impact on Users**: The lack of access to timely patches exposes customers to vulnerabilities, undermining the security of their infrastructure and increasing their susceptibility to potential exploits while using outdated software.

This scenario underscores the critical importance of maintaining updated support contracts or subscription plans to ensure timely access to vital security updates, emphasizing a broader concern in the IT and security landscape regarding vendor policies and customer rights concerning software security.