The vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger this vulnerability by sending a specially crafted network packet potentially leading to remote code execution.
An attacker with network access to vCenter Server can send a specially crafted network packet that triggers a heap-overflow in the DCERPC protocol implementation. The error classified as CWE-122 (heap-based buffer overflow) and CWE-787 (out-of-bounds write) allows arbitrary code execution in the context of the vulnerable process. The attack does not require authentication or user interaction, making it particularly dangerous.
Successful exploitation of this vulnerability may lead to complete remote takeover of the vCenter Server, including breach of confidentiality, integrity, and availability of the managed virtualization infrastructure.
Patches available from the vendor must be applied immediately in accordance with references published by Broadcom at: https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24968
VMware vCenter Server and VMware Cloud Foundation — specific versions indicated in vendor references (Broadcom Security Advisory #24968)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HVMware Cloud Foundation
APPVmware4.0 – 5.2 (excl.)VMware Vcenter Server
APPVmware7.08.0
CISA KEV — detailsi
- Vendori
- VMware ↗
- Producti
- vCenter Server
- Added to KEVi
- November 20, 2024
- Remediation deadline (US Federal)i
- December 11, 2024(overdue)
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
VMware vCenter Server contains a heap-based buffer overflow vulnerability in the implementation of the DCERPC protocol. This vulnerability could allow an attacker with network access to the vCenter Server to execute remote code by sending a specially crafted packet.
Related vulnerabilities
VMware vCenter: path traversal w Syslog umożliwia RCE
VMware ESXi/Workstation: TOCTOU umożliwia ucieczkę z VM przez VMX process
Heap overflow w VMware vCenter Server via protokół DCERPC — RCE
VMware vCenter Server — RCE przez out-of-bounds write w protokole DCERPC
RCE w VMware Workspace ONE Access i Identity Manager poprzez server-side template injection