Junglewise Threat Intelligence

CVE-2024-38812: VMware vCenter Server Heap-Based Buffer Overflow Vulnerability

CVE-2024-38812 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2024-11-20

Technologies: Broadcom vCenter Server, VMware Cloud Foundation. Vendors: Broadcom, VMware.

Executive brief

VMware vCenter Server contains a heap-based buffer overflow vulnerability in its DCERPC protocol implementation. A remote attacker can exploit this by sending a specially crafted network packet, potentially resulting in remote code execution.

Affected products

  • VMware vCenter Server 7.0, 8.0

Timeline

  • 2024-11-20: disclosed
  • 2024-11-20: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2024-11-20: exploited: Reported as exploited in the wild.

Related threats