Executive brief
Broadcom vCenter Server, a central management platform for VMware virtualization environments, contains a critical security flaw. A remote attacker can exploit this vulnerability by sending malicious network traffic to the server, potentially gaining full control over the management console. This could lead to a total compromise of the virtual infrastructure, including unauthorized access to hosted virtual machines and data.
Technical details
A heap-based buffer overflow (out-of-bounds write) exists in the Distributed Computing Environment / Remote Procedure Call (DCERPC) protocol implementation within VMware vCenter Server. The vulnerability is triggered when the service processes specially crafted network packets. An unauthenticated attacker with network access to the vCenter Server can exploit this to execute arbitrary code with high privileges. This vulnerability affects vCenter Server versions 7.0 and 8.0, as well as VMware Cloud Foundation. Patches have been released by the vendor to address this issue.
Affected products
- Broadcom vCenter Server 7.0, 8.0, and Cloud Foundation 4.x/5.x
Timeline
- 2024-11-21: advisory: Broadcom published the initial security advisory.
- 2026-01-23: kev added: CISA added the vulnerability to the Known Exploited Vulnerabilities (KEV) catalog.
- 2026-01-23: exploited: Vulnerability confirmed to be exploited in the wild.