CRITICAL🚩 CISA KEV⚡ EXPLOIT🇵🇱 Wersja polska

CVE-2024-38812

CVSS 9.8v3.1pub. 2024-09-17upd. 2025-10-31

The vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger this vulnerability by sending a specially crafted network packet potentially leading to remote code execution.

🤖 AI Analysis
How it works

An attacker with network access to vCenter Server can send a specially crafted network packet that triggers a heap-overflow in the DCERPC protocol implementation. The error classified as CWE-122 (heap-based buffer overflow) and CWE-787 (out-of-bounds write) allows arbitrary code execution in the context of the vulnerable process. The attack does not require authentication or user interaction, making it particularly dangerous.

Impact

Successful exploitation of this vulnerability may lead to complete remote takeover of the vCenter Server, including breach of confidentiality, integrity, and availability of the managed virtualization infrastructure.

Mitigation & patch

Patches available from the vendor must be applied immediately in accordance with references published by Broadcom at: https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24968

Who is affected

VMware vCenter Server and VMware Cloud Foundation — specific versions indicated in vendor references (Broadcom Security Advisory #24968)

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • VMware Cloud Foundation

    APP
    Vmware
    4.0 – 5.2 (excl.)
  • VMware Vcenter Server

    APP
    Vmware
    7.08.0

CISA KEV — detailsi

Vendori
VMware
Producti
vCenter Server
Added to KEVi
November 20, 2024
Remediation deadline (US Federal)i
December 11, 2024(overdue)
Required action (CISA)i

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CISA descriptioni

VMware vCenter Server contains a heap-based buffer overflow vulnerability in the implementation of the DCERPC protocol. This vulnerability could allow an attacker with network access to the vCenter Server to execute remote code by sending a specially crafted packet.

🔴
IMMEDIATE ACTION
Actively exploited in the wild (CISA KEV). Patch immediately.
CISA DEADLINE: 11 grudnia 2024
Tags
RCE
CWE
References

Related vulnerabilities

CVE-2026-59310CRITICAL9.8⚠ KEVPL ✓same product

VMware vCenter: path traversal w Syslog umożliwia RCE

CVE-2025-22224CRITICAL9.3⚠ KEVPL ✓same product

VMware ESXi/Workstation: TOCTOU umożliwia ucieczkę z VM przez VMX process

CVE-2024-37079CRITICAL9.8⚠ KEVPL ✓same product

Heap overflow w VMware vCenter Server via protokół DCERPC — RCE

CVE-2023-34048CRITICAL9.8⚠ KEVPL ✓same product

VMware vCenter Server — RCE przez out-of-bounds write w protokole DCERPC

CVE-2022-22954CRITICAL9.8⚠ KEVPL ✓same product

RCE w VMware Workspace ONE Access i Identity Manager poprzez server-side template injection