PT-2024-6262 · Vmware · Vmware Vcenter Server+1

Srs

+1

·

Published

2024-09-17

·

Updated

2026-03-10

·

CVE-2024-38812

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions VMware vCenter Server versions 7.0 through 8.0 VMware Cloud Foundation versions 7.0 through 8.0
Description VMware vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access can exploit this vulnerability by sending a specially crafted network packet, potentially leading to remote code execution. This vulnerability, tracked as CVE-2024-38812, has a CVSS score of 9.8 and is actively exploited. The initial patch released in September 2024 did not fully address the vulnerability, requiring a subsequent update. The vulnerability was also demonstrated during a hacking contest. Over 2,800 systems are exposed online.
Recommendations Apply the latest security updates for VMware vCenter Server version 7.0 Update 3t or later. Apply the latest security updates for VMware vCenter Server version 8.0 Update 2e or later. Apply the latest security updates for VMware Cloud Foundation version 7.0 Update 3t or later. Apply the latest security updates for VMware Cloud Foundation version 8.0 Update 2e or later.

Fix

RCE

Memory Corruption

Heap Based Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-07209
CVE-2024-38812

Affected Products

Vmware Vcenter
Vmware Vcenter Server