PT-2024-4293 · Vmware · Vcenter Server+1

Hao Zheng

+3

·

Published

2024-06-18

·

Updated

2026-02-23

·

CVE-2024-37080

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions VMware vCenter Server (affected versions not specified)
Description The issue is a heap-overflow vulnerability in the implementation of the DCERPC protocol within VMware vCenter Server. A malicious actor with network access can trigger this by sending a specially crafted network packet, potentially leading to remote code execution. The vulnerability is due to improper memory handling during the processing of DCERPC protocol requests. The DCERPC protocol is a remote procedure call mechanism used for communication between different components of the vCenter Server. Exploitation allows an unauthenticated attacker to execute arbitrary code on the server.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Memory Corruption

Heap Based Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-04780
CVE-2024-37080

Affected Products

Vmware Vcenter
Vcenter Server