9.8
CVE-2024-37079
- EPSS 22.38%
- Veröffentlicht 18.06.2024 06:15:11
- Zuletzt bearbeitet 26.01.2026 14:52:05
- Erkennungen
vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger this vulnerability by sending a specially crafted network packet potentially leading to remote code execution.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
VMware ≫ Cloud Foundation Version >= 4.0 < 5.2
VMware ≫ vCenter Server Version 8.0 Update -
VMware ≫ vCenter Server Version 8.0 Update a
VMware ≫ vCenter Server Version 8.0 Update b
VMware ≫ vCenter Server Version 8.0 Update c
VMware ≫ vCenter Server Version 8.0 Update update1
VMware ≫ vCenter Server Version 8.0 Update update1a
VMware ≫ vCenter Server Version 8.0 Update update1b
VMware ≫ vCenter Server Version 8.0 Update update1c
VMware ≫ vCenter Server Version 8.0 Update update1d
VMware ≫ vCenter Server Version 8.0 Update update2
VMware ≫ vCenter Server Version 8.0 Update update2a
VMware ≫ vCenter Server Version 8.0 Update update2b
VMware ≫ vCenter Server Version 8.0 Update update2c
VMware ≫ vCenter Server Version 7.0 Update -
VMware ≫ vCenter Server Version 7.0 Update a
VMware ≫ vCenter Server Version 7.0 Update b
VMware ≫ vCenter Server Version 7.0 Update c
VMware ≫ vCenter Server Version 7.0 Update d
VMware ≫ vCenter Server Version 7.0 Update update1
VMware ≫ vCenter Server Version 7.0 Update update1a
VMware ≫ vCenter Server Version 7.0 Update update1c
VMware ≫ vCenter Server Version 7.0 Update update1d
VMware ≫ vCenter Server Version 7.0 Update update2
VMware ≫ vCenter Server Version 7.0 Update update2a
VMware ≫ vCenter Server Version 7.0 Update update2b
VMware ≫ vCenter Server Version 7.0 Update update2c
VMware ≫ vCenter Server Version 7.0 Update update2d
VMware ≫ vCenter Server Version 7.0 Update update3
VMware ≫ vCenter Server Version 7.0 Update update3a
VMware ≫ vCenter Server Version 7.0 Update update3c
VMware ≫ vCenter Server Version 7.0 Update update3d
VMware ≫ vCenter Server Version 7.0 Update update3e
VMware ≫ vCenter Server Version 7.0 Update update3f
VMware ≫ vCenter Server Version 7.0 Update update3g
VMware ≫ vCenter Server Version 7.0 Update update3h
VMware ≫ vCenter Server Version 7.0 Update update3i
VMware ≫ vCenter Server Version 7.0 Update update3j
VMware ≫ vCenter Server Version 7.0 Update update3k
VMware ≫ vCenter Server Version 7.0 Update update3l
VMware ≫ vCenter Server Version 7.0 Update update3m
VMware ≫ vCenter Server Version 7.0 Update update3n
VMware ≫ vCenter Server Version 7.0 Update update3o
VMware ≫ vCenter Server Version 7.0 Update update3p
23.01.2026: CISA Known Exploited Vulnerabilities (KEV) Catalog
Broadcom VMware vCenter Server Out-of-bounds Write Vulnerability
SchwachstelleBroadcom VMware vCenter Server contains an out-of-bounds write vulnerability in the implementation of the DCERPC protocol. This could allow a malicious actor with network access to vCenter Server to send specially crafted network packets, potentially leading to remote code execution.
BeschreibungApply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Erforderliche Maßnahmen| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 22.38% | 0.974 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
| VMware | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
CWE-787 Out-of-bounds Write
The product writes data past the end, or before the beginning, of the intended buffer.
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24453
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-37079