Known Exploited Vulnerability
9.8
CRITICAL CVSS 3.1
CVE-2024-37079
Broadcom VMware vCenter Server Out-of-bounds Write Vulnerability - [Actively Exploited]
Description

vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger this vulnerability by sending a specially crafted network packet potentially leading to remote code execution.

INFO

Published Date :

June 18, 2024, 6:15 a.m.

Last Modified :

Jan. 26, 2026, 2:52 p.m.

Remotely Exploit :

Yes !
CISA Notification
CISA KEV (Known Exploited Vulnerabilities)

For the benefit of the cybersecurity community and network defenders—and to help every organization better manage vulnerabilities and keep pace with threat activity—CISA maintains the authoritative source of vulnerabilities that have been exploited in the wild.

Description :

Broadcom VMware vCenter Server contains an out-of-bounds write vulnerability in the implementation of the DCERPC protocol. This could allow a malicious actor with network access to vCenter Server to send specially crafted network packets, potentially leading to remote code execution.

Required Action :

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Notes :

https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24453 ; https://nvd.nist.gov/vuln/detail/CVE-2024-37079

Affected Products

The following products are affected by CVE-2024-37079 vulnerability. Even if cvefeed.io is aware of the exact versions of the products that are affected, the information is not represented in the table below.

ID Vendor Product Action
1 Vmware vcenter_server
2 Vmware cloud_foundation
CVSS Scores
The Common Vulnerability Scoring System is a standardized framework for assessing the severity of vulnerabilities in software and systems. We collect and displays CVSS scores from various sources for each CVE.
Score Version Severity Vector Exploitability Score Impact Score Source
CVSS 3.1 CRITICAL [email protected]
CVSS 3.1 CRITICAL [email protected]
Solution
This information is provided by the 3rd party feeds.
  • Upgrade to VMware vCenter Server 7.0U3r, or 8.0U2d or later.
Public PoC/Exploit Available at Github

CVE-2024-37079 has a 4 public PoC/Exploit available at Github. Go to the Public Exploits tab to see the list.

References to Advisories, Solutions, and Tools

Here, you will find a curated list of external links that provide in-depth information, practical solutions, and valuable tools related to CVE-2024-37079.

URL Resource
https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24453 Patch Vendor Advisory
https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24453 Patch Vendor Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-37079 US Government Resource
CWE - Common Weakness Enumeration

While CVE identifies specific instances of vulnerabilities, CWE categorizes the common flaws or weaknesses that can lead to vulnerabilities. CVE-2024-37079 is associated with the following CWEs:

Common Attack Pattern Enumeration and Classification (CAPEC)

Common Attack Pattern Enumeration and Classification (CAPEC) stores attack patterns, which are descriptions of the common attributes and approaches employed by adversaries to exploit the CVE-2024-37079 weaknesses.

We scan GitHub repositories to detect new proof-of-concept exploits. Following list is a collection of public exploits and proof-of-concepts, which have been published on GitHub (sorted by the most recently updated).

None

Updated: 4 months, 3 weeks ago
0 stars 0 fork 0 watcher
Born at : Sept. 9, 2025, 6:09 a.m. This repo has been linked 24 different CVEs too.

None

Updated: 7 months, 1 week ago
4 stars 0 fork 0 watcher
Born at : Feb. 2, 2025, 7:45 a.m. This repo has been linked 12 different CVEs too.

PoC for CVE-2024-37079 Vcenter server unauthenticated RCE.

Updated: 1 year, 7 months ago
0 stars 0 fork 0 watcher
Born at : June 20, 2024, 1:09 a.m. This repo has been linked 1 different CVEs too.

None

Updated: 1 week, 5 days ago
0 stars 0 fork 0 watcher
Born at : Jan. 14, 2023, 11:38 a.m. This repo has been linked 1 different CVEs too.

Results are limited to the first 15 repositories due to potential performance issues.

The following list is the news that have been mention CVE-2024-37079 vulnerability anywhere in the article.

  • The Hacker News
Researchers Uncover Chrome Extensions Abusing Affiliate Links and Stealing ChatGPT Access

Cybersecurity researchers have discovered malicious Google Chrome extensions that come with capabilities to hijack affiliate links, steal data, and collect OpenAI ChatGPT authentication tokens. One of ... Read more

Published Date: Jan 30, 2026 (6 days, 5 hours ago)
  • The Hacker News
SmarterMail Fixes Critical Unauthenticated RCE Flaw with CVSS 9.3 Score

SmarterTools has addressed two more security flaws in SmarterMail email software, including one critical security flaw that could result in arbitrary code execution. The vulnerability, tracked as CVE- ... Read more

Published Date: Jan 30, 2026 (6 days, 12 hours ago)
  • The Hacker News
Two Ivanti EPMM Zero-Day RCE Flaws Actively Exploited, Security Updates Released

Ivanti has rolled out security updates to address two security flaws impacting Ivanti Endpoint Manager Mobile (EPMM) that have been exploited in zero-day attacks, one of which has been added by the U. ... Read more

Published Date: Jan 30, 2026 (6 days, 14 hours ago)
  • The Hacker News
ThreatsDay Bulletin: New RCEs, Darknet Busts, Kernel Bugs & 25+ More Stories

This week's updates show how small changes can create real problems. Not loud incidents, but quiet shifts that are easy to miss until they add up. The kind that affects systems people rely on every da ... Read more

Published Date: Jan 29, 2026 (1 week ago)
  • The Hacker News
Survey of 100+ Energy Systems Reveals Critical OT Cybersecurity Gaps

A study by OMICRON has revealed widespread cybersecurity gaps in the operational technology (OT) networks of substations, power plants, and control centers worldwide. Drawing on data from more than 10 ... Read more

Published Date: Jan 29, 2026 (1 week ago)
  • The Cyber Express
Nation-State Hackers, Cybercriminals Weaponize Patched WinRAR Flaw Despite Six-Month-Old Fix

Russian and Chinese espionage groups continue to exploit an N-day vulnerability (CVE-2025-8088) in WinRAR alongside financially motivated actors, all leveraging a path traversal vulnerability that dro ... Read more

Published Date: Jan 29, 2026 (1 week ago)
  • The Hacker News
SolarWinds Fixes Four Critical Web Help Desk Flaws With Unauthenticated RCE and Auth Bypass

SolarWinds has released security updates to address multiple security vulnerabilities impacting SolarWinds Web Help Desk, including four critical vulnerabilities that could result in authentication by ... Read more

Published Date: Jan 29, 2026 (1 week ago)
  • The Cyber Express
Malicious Open Source Software Packages Neared 500,000 in 2025

Malicious open source software packages have become a critical problem threatening the software supply chain. That’s one of the major takeaways of a new report titled “State of the Software Supply Cha ... Read more

Published Date: Jan 28, 2026 (1 week ago)
  • The Hacker News
Critical vm2 Node.js Flaw Allows Sandbox Escape and Arbitrary Code Execution

A critical sandbox escape vulnerability has been disclosed in the popular vm2 Node.js library that, if successfully exploited, could allow attackers to run arbitrary code on the underlying operating s ... Read more

Published Date: Jan 28, 2026 (1 week, 1 day ago)
  • The Hacker News
Two High-Severity n8n Flaws Allow Authenticated Remote Code Execution

Cybersecurity researchers have disclosed two new security flaws in the n8n workflow automation platform, including a crucial vulnerability that could result in remote code execution. The weaknesses, d ... Read more

Published Date: Jan 28, 2026 (1 week, 1 day ago)
  • The Hacker News
Google Warns of Active Exploitation of WinRAR Vulnerability CVE-2025-8088

Google on Tuesday revealed that multiple threat actors, including nation-state adversaries and financially motivated groups, are exploiting a now-patched critical security flaw in RARLAB WinRAR to est ... Read more

Published Date: Jan 28, 2026 (1 week, 1 day ago)
  • The Cyber Express
Hackers Exploit React2Shell Vulnerability to Deploy Miners and Botnets Worldwide

Threat actors have been actively exploiting a critical vulnerability in React Server Components, tracked as CVE-2025-55182 and commonly referred to as React2Shell, to compromise systems across multipl ... Read more

Published Date: Jan 28, 2026 (1 week, 1 day ago)
  • The Hacker News
Fortinet Patches CVE-2026-24858 After Active FortiOS SSO Exploitation Detected

Fortinet has begun releasing security updates to address a critical flaw impacting FortiOS that has come under active exploitation in the wild. The vulnerability, assigned the CVE identifier CVE-2026- ... Read more

Published Date: Jan 28, 2026 (1 week, 1 day ago)
  • The Hacker News
Critical Grist-Core Vulnerability Allows RCE Attacks via Spreadsheet Formulas

A critical security flaw has been disclosed in Grist‑Core, an open-source, self-hosted version of the Grist relational spreadsheet-database, that could result in remote code execution. The vulnerabili ... Read more

Published Date: Jan 27, 2026 (1 week, 2 days ago)
  • The Cyber Express
CISA Flags Actively Exploited VMware vCenter RCE Flaw in KEV Catalog

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical vulnerability affecting VMware vCenter Server to its Known Exploited Vulnerabilities (KEV) catalog, confirming tha ... Read more

Published Date: Jan 27, 2026 (1 week, 2 days ago)
  • The Hacker News
China-Linked Hackers Have Used the PeckBirdy JavaScript C2 Framework Since 2023

Cybersecurity researchers have discovered a JScript-based command-and-control (C2) framework called PeckBirdy that has been put to use by China-aligned APT actors since 2023 to target multiple environ ... Read more

Published Date: Jan 27, 2026 (1 week, 2 days ago)
  • The Hacker News
Microsoft Office Zero-Day (CVE-2026-21509) - Emergency Patch Issued for Active Exploitation

Microsoft on Monday issued out-of-band security patches for a high-severity Microsoft Office zero-day vulnerability exploited in attacks. The vulnerability, tracked as CVE-2026-21509, carries a CVSS s ... Read more

Published Date: Jan 27, 2026 (1 week, 2 days ago)
  • The Hacker News
Malicious VS Code AI Extensions with 1.5 Million Installs Steal Developer Source Code

Cybersecurity researchers have discovered two malicious Microsoft Visual Studio Code (VS Code) extensions that are advertised as artificial intelligence (AI)-powered coding assistants, but also harbor ... Read more

Published Date: Jan 26, 2026 (1 week, 3 days ago)
  • security.nl
Broadcom meldt misbruik van kritieke kwetsbaarheid in VMware vCenter

Aanvallers maken actief misbruik van een kritieke kwetsbaarheid in VMware vCenter-servers waarvoor op 18 juni 2024 beveiligingsupdates verschenen, zo melden Broadcom en het Amerikaanse cyberagentschap ... Read more

Published Date: Jan 26, 2026 (1 week, 3 days ago)
  • BleepingComputer
CISA says critical VMware RCE flaw now actively exploited

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has flagged a critical VMware vCenter Server vulnerability as actively exploited and ordered federal agencies to secure their servers w ... Read more

Published Date: Jan 26, 2026 (1 week, 3 days ago)

The following table lists the changes that have been made to the CVE-2024-37079 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability's severity, exploitability, or other characteristics.

  • Modified Analysis by [email protected]

    Jan. 26, 2026

    Action Type Old Value New Value
    Added CPE Configuration OR *cpe:2.3:a:vmware:cloud_foundation:*:*:*:*:*:*:*:* versions from (including) 4.0 up to (excluding) 5.2
    Removed CPE Configuration AND OR cpe:2.3:a:vmware:cloud_foundation:*:*:*:*:*:*:*:* versions from (including) 4.0 up to (excluding) 5.2 OR *cpe:2.3:a:vmware:vcenter_server:7.0:-:*:*:*:*:*:* *cpe:2.3:a:vmware:vcenter_server:7.0:d:*:*:*:*:*:* *cpe:2.3:a:vmware:vcenter_server:7.0:c:*:*:*:*:*:* *cpe:2.3:a:vmware:vcenter_server:7.0:b:*:*:*:*:*:* *cpe:2.3:a:vmware:vcenter_server:7.0:a:*:*:*:*:*:* *cpe:2.3:a:vmware:vcenter_server:7.0:update1a:*:*:*:*:*:* *cpe:2.3:a:vmware:vcenter_server:7.0:update1:*:*:*:*:*:* *cpe:2.3:a:vmware:vcenter_server:7.0:update1c:*:*:*:*:*:* *cpe:2.3:a:vmware:vcenter_server:7.0:update1d:*:*:*:*:*:* *cpe:2.3:a:vmware:vcenter_server:7.0:update2:*:*:*:*:*:* *cpe:2.3:a:vmware:vcenter_server:7.0:update2a:*:*:*:*:*:* *cpe:2.3:a:vmware:vcenter_server:7.0:update2b:*:*:*:*:*:* *cpe:2.3:a:vmware:vcenter_server:7.0:update2c:*:*:*:*:*:* *cpe:2.3:a:vmware:vcenter_server:7.0:update2d:*:*:*:*:*:* *cpe:2.3:a:vmware:vcenter_server:7.0:update3:*:*:*:*:*:* *cpe:2.3:a:vmware:vcenter_server:7.0:update3a:*:*:*:*:*:* *cpe:2.3:a:vmware:vcenter_server:7.0:update3c:*:*:*:*:*:* *cpe:2.3:a:vmware:vcenter_server:7.0:update3d:*:*:*:*:*:* *cpe:2.3:a:vmware:vcenter_server:7.0:update3e:*:*:*:*:*:* *cpe:2.3:a:vmware:vcenter_server:7.0:update3f:*:*:*:*:*:* *cpe:2.3:a:vmware:vcenter_server:7.0:update3g:*:*:*:*:*:* *cpe:2.3:a:vmware:vcenter_server:7.0:update3h:*:*:*:*:*:* *cpe:2.3:a:vmware:vcenter_server:7.0:update3j:*:*:*:*:*:* *cpe:2.3:a:vmware:vcenter_server:7.0:update3k:*:*:*:*:*:* *cpe:2.3:a:vmware:vcenter_server:7.0:update3l:*:*:*:*:*:* *cpe:2.3:a:vmware:vcenter_server:7.0:update3i:*:*:*:*:*:* *cpe:2.3:a:vmware:vcenter_server:8.0:update1:*:*:*:*:*:* *cpe:2.3:a:vmware:vcenter_server:8.0:update1a:*:*:*:*:*:* *cpe:2.3:a:vmware:vcenter_server:8.0:a:*:*:*:*:*:* *cpe:2.3:a:vmware:vcenter_server:8.0:b:*:*:*:*:*:* *cpe:2.3:a:vmware:vcenter_server:8.0:c:*:*:*:*:*:* *cpe:2.3:a:vmware:vcenter_server:8.0:-:*:*:*:*:*:* *cpe:2.3:a:vmware:vcenter_server:8.0:update1c:*:*:*:*:*:* *cpe:2.3:a:vmware:vcenter_server:7.0:update3n:*:*:*:*:*:* *cpe:2.3:a:vmware:vcenter_server:8.0:update1b:*:*:*:*:*:* *cpe:2.3:a:vmware:vcenter_server:7.0:update3m:*:*:*:*:*:* *cpe:2.3:a:vmware:vcenter_server:8.0:update1d:*:*:*:*:*:* *cpe:2.3:a:vmware:vcenter_server:7.0:update3o:*:*:*:*:*:* *cpe:2.3:a:vmware:vcenter_server:7.0:update3p:*:*:*:*:*:* *cpe:2.3:a:vmware:vcenter_server:8.0:update2:*:*:*:*:*:* *cpe:2.3:a:vmware:vcenter_server:8.0:update2a:*:*:*:*:*:* *cpe:2.3:a:vmware:vcenter_server:8.0:update2b:*:*:*:*:*:* *cpe:2.3:a:vmware:vcenter_server:8.0:update2c:*:*:*:*:*:*
    Added Reference Type CISA-ADP: https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-37079 Types: US Government Resource
  • CVE Modified by 134c704f-9b21-4f2e-91b3-4a467353bcc0

    Jan. 23, 2026

    Action Type Old Value New Value
    Added CWE CWE-787
    Removed CWE CWE-122
    Added Reference https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-37079
  • CVE Modified by 134c704f-9b21-4f2e-91b3-4a467353bcc0

    Jan. 22, 2026

    Action Type Old Value New Value
    Added CWE CWE-122
    Removed CWE CWE-787
  • CVE Modified by 134c704f-9b21-4f2e-91b3-4a467353bcc0

    Mar. 14, 2025

    Action Type Old Value New Value
    Added CWE CWE-787
  • CVE Modified by af854a3a-2127-422b-91ae-364da2661108

    Nov. 21, 2024

    Action Type Old Value New Value
    Added Reference https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24453
  • Initial Analysis by [email protected]

    Aug. 30, 2024

    Action Type Old Value New Value
    Added CVSS V3.1 NIST AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
    Changed Reference Type https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24453 No Types Assigned https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24453 Patch, Vendor Advisory
    Added CWE NIST CWE-787
    Added CPE Configuration OR *cpe:2.3:a:vmware:vcenter_server:8.0:-:*:*:*:*:*:* *cpe:2.3:a:vmware:vcenter_server:8.0:a:*:*:*:*:*:* *cpe:2.3:a:vmware:vcenter_server:8.0:b:*:*:*:*:*:* *cpe:2.3:a:vmware:vcenter_server:8.0:c:*:*:*:*:*:* *cpe:2.3:a:vmware:vcenter_server:8.0:update1:*:*:*:*:*:* *cpe:2.3:a:vmware:vcenter_server:8.0:update1a:*:*:*:*:*:* *cpe:2.3:a:vmware:vcenter_server:8.0:update1b:*:*:*:*:*:* *cpe:2.3:a:vmware:vcenter_server:8.0:update1c:*:*:*:*:*:* *cpe:2.3:a:vmware:vcenter_server:8.0:update1d:*:*:*:*:*:* *cpe:2.3:a:vmware:vcenter_server:8.0:update2:*:*:*:*:*:* *cpe:2.3:a:vmware:vcenter_server:8.0:update2a:*:*:*:*:*:* *cpe:2.3:a:vmware:vcenter_server:8.0:update2b:*:*:*:*:*:* *cpe:2.3:a:vmware:vcenter_server:8.0:update2c:*:*:*:*:*:*
    Added CPE Configuration OR *cpe:2.3:a:vmware:vcenter_server:7.0:-:*:*:*:*:*:* *cpe:2.3:a:vmware:vcenter_server:7.0:a:*:*:*:*:*:* *cpe:2.3:a:vmware:vcenter_server:7.0:b:*:*:*:*:*:* *cpe:2.3:a:vmware:vcenter_server:7.0:c:*:*:*:*:*:* *cpe:2.3:a:vmware:vcenter_server:7.0:d:*:*:*:*:*:* *cpe:2.3:a:vmware:vcenter_server:7.0:update1:*:*:*:*:*:* *cpe:2.3:a:vmware:vcenter_server:7.0:update1a:*:*:*:*:*:* *cpe:2.3:a:vmware:vcenter_server:7.0:update1c:*:*:*:*:*:* *cpe:2.3:a:vmware:vcenter_server:7.0:update1d:*:*:*:*:*:* *cpe:2.3:a:vmware:vcenter_server:7.0:update2:*:*:*:*:*:* *cpe:2.3:a:vmware:vcenter_server:7.0:update2a:*:*:*:*:*:* *cpe:2.3:a:vmware:vcenter_server:7.0:update2b:*:*:*:*:*:* *cpe:2.3:a:vmware:vcenter_server:7.0:update2c:*:*:*:*:*:* *cpe:2.3:a:vmware:vcenter_server:7.0:update2d:*:*:*:*:*:* *cpe:2.3:a:vmware:vcenter_server:7.0:update3:*:*:*:*:*:* *cpe:2.3:a:vmware:vcenter_server:7.0:update3a:*:*:*:*:*:* *cpe:2.3:a:vmware:vcenter_server:7.0:update3c:*:*:*:*:*:* *cpe:2.3:a:vmware:vcenter_server:7.0:update3d:*:*:*:*:*:* *cpe:2.3:a:vmware:vcenter_server:7.0:update3e:*:*:*:*:*:* *cpe:2.3:a:vmware:vcenter_server:7.0:update3f:*:*:*:*:*:* *cpe:2.3:a:vmware:vcenter_server:7.0:update3g:*:*:*:*:*:* *cpe:2.3:a:vmware:vcenter_server:7.0:update3h:*:*:*:*:*:* *cpe:2.3:a:vmware:vcenter_server:7.0:update3i:*:*:*:*:*:* *cpe:2.3:a:vmware:vcenter_server:7.0:update3j:*:*:*:*:*:* *cpe:2.3:a:vmware:vcenter_server:7.0:update3k:*:*:*:*:*:* *cpe:2.3:a:vmware:vcenter_server:7.0:update3l:*:*:*:*:*:* *cpe:2.3:a:vmware:vcenter_server:7.0:update3m:*:*:*:*:*:* *cpe:2.3:a:vmware:vcenter_server:7.0:update3n:*:*:*:*:*:* *cpe:2.3:a:vmware:vcenter_server:7.0:update3o:*:*:*:*:*:* *cpe:2.3:a:vmware:vcenter_server:7.0:update3p:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:a:vmware:vcenter_server:7.0:-:*:*:*:*:*:* *cpe:2.3:a:vmware:vcenter_server:7.0:a:*:*:*:*:*:* *cpe:2.3:a:vmware:vcenter_server:7.0:b:*:*:*:*:*:* *cpe:2.3:a:vmware:vcenter_server:7.0:c:*:*:*:*:*:* *cpe:2.3:a:vmware:vcenter_server:7.0:d:*:*:*:*:*:* *cpe:2.3:a:vmware:vcenter_server:7.0:update1:*:*:*:*:*:* *cpe:2.3:a:vmware:vcenter_server:7.0:update1a:*:*:*:*:*:* *cpe:2.3:a:vmware:vcenter_server:7.0:update1c:*:*:*:*:*:* *cpe:2.3:a:vmware:vcenter_server:7.0:update1d:*:*:*:*:*:* *cpe:2.3:a:vmware:vcenter_server:7.0:update2:*:*:*:*:*:* *cpe:2.3:a:vmware:vcenter_server:7.0:update2a:*:*:*:*:*:* *cpe:2.3:a:vmware:vcenter_server:7.0:update2b:*:*:*:*:*:* *cpe:2.3:a:vmware:vcenter_server:7.0:update2c:*:*:*:*:*:* *cpe:2.3:a:vmware:vcenter_server:7.0:update2d:*:*:*:*:*:* *cpe:2.3:a:vmware:vcenter_server:7.0:update3:*:*:*:*:*:* *cpe:2.3:a:vmware:vcenter_server:7.0:update3a:*:*:*:*:*:* *cpe:2.3:a:vmware:vcenter_server:7.0:update3c:*:*:*:*:*:* *cpe:2.3:a:vmware:vcenter_server:7.0:update3d:*:*:*:*:*:* *cpe:2.3:a:vmware:vcenter_server:7.0:update3e:*:*:*:*:*:* *cpe:2.3:a:vmware:vcenter_server:7.0:update3f:*:*:*:*:*:* *cpe:2.3:a:vmware:vcenter_server:7.0:update3g:*:*:*:*:*:* *cpe:2.3:a:vmware:vcenter_server:7.0:update3h:*:*:*:*:*:* *cpe:2.3:a:vmware:vcenter_server:7.0:update3i:*:*:*:*:*:* *cpe:2.3:a:vmware:vcenter_server:7.0:update3j:*:*:*:*:*:* *cpe:2.3:a:vmware:vcenter_server:7.0:update3k:*:*:*:*:*:* *cpe:2.3:a:vmware:vcenter_server:7.0:update3l:*:*:*:*:*:* *cpe:2.3:a:vmware:vcenter_server:7.0:update3m:*:*:*:*:*:* *cpe:2.3:a:vmware:vcenter_server:7.0:update3n:*:*:*:*:*:* *cpe:2.3:a:vmware:vcenter_server:7.0:update3o:*:*:*:*:*:* *cpe:2.3:a:vmware:vcenter_server:7.0:update3p:*:*:*:*:*:* *cpe:2.3:a:vmware:vcenter_server:8.0:-:*:*:*:*:*:* *cpe:2.3:a:vmware:vcenter_server:8.0:a:*:*:*:*:*:* *cpe:2.3:a:vmware:vcenter_server:8.0:b:*:*:*:*:*:* *cpe:2.3:a:vmware:vcenter_server:8.0:c:*:*:*:*:*:* *cpe:2.3:a:vmware:vcenter_server:8.0:update1:*:*:*:*:*:* *cpe:2.3:a:vmware:vcenter_server:8.0:update1a:*:*:*:*:*:* *cpe:2.3:a:vmware:vcenter_server:8.0:update1b:*:*:*:*:*:* *cpe:2.3:a:vmware:vcenter_server:8.0:update1c:*:*:*:*:*:* *cpe:2.3:a:vmware:vcenter_server:8.0:update1d:*:*:*:*:*:* *cpe:2.3:a:vmware:vcenter_server:8.0:update2:*:*:*:*:*:* *cpe:2.3:a:vmware:vcenter_server:8.0:update2a:*:*:*:*:*:* *cpe:2.3:a:vmware:vcenter_server:8.0:update2b:*:*:*:*:*:* *cpe:2.3:a:vmware:vcenter_server:8.0:update2c:*:*:*:*:*:* OR cpe:2.3:a:vmware:cloud_foundation:*:*:*:*:*:*:*:* versions from (including) 4.0 up to (excluding) 5.2
  • CVE Received by [email protected]

    Jun. 18, 2024

    Action Type Old Value New Value
    Added Description vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger this vulnerability by sending a specially crafted network packet potentially leading to remote code execution.
    Added Reference VMware https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24453 [No types assigned]
    Added CVSS V3.1 VMware AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS is a daily estimate of the probability of exploitation activity being observed over the next 30 days. Following chart shows the EPSS score history of the vulnerability.
Vulnerability Scoring Details
Base CVSS Score: 9.8
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact