CVE-2024-38812
VMware vCenter Server Heap-Based Buffer Overflow Vulnerability
Does this matter?
Known to be exploited in the wild (CISA KEV, CISA remediation deadline 11 December 2024). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.
Description
The vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger this vulnerability by sending a specially crafted network packet potentially leading to remote code execution.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 54.57% probability · 99th percentile
- CISA KEV
- Listed 20 November 2024 · due 11 December 2024
- Weakness
- CWE-122, CWE-787
- Affected
- vmware/cloud foundation · vmware/vcenter server
- Source
- security@vmware.com
CISA notes
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24968 ; https://nvd.nist.gov/vuln/detail/CVE-2024-38812
References
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.