CRITICAL

CVE-2024-38812

Vmware Cloud Foundation 2024-09-17 CVSS v3.1
CVSS
9.8
KEV

Description

The vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger this vulnerability by sending a specially crafted network packet potentially leading to remote code execution.

Summary dbcve.org

vCenter Server contains a heap-overflow vulnerability in its DCERPC protocol implementation. An unauthenticated attacker with network access can send specially crafted packets to trigger the overflow, potentially achieving remote code execution. The critical severity (CVSS 9.8) reflects the ease of network-based exploitation and complete impact on confidentiality, integrity, and availability.

Mitigation

Apply the official VMware security patch for CVE-2024-38812 to vCenter Server immediately. If patching is not immediately possible, restrict network access to vCenter Server management interfaces using network segmentation or firewall rules to limit exposure to untrusted networks.

Weakness (CWE)

CWE-122 Heap-based Buffer Overflow
CWE-787 Out-of-bounds Write

EPSS Score

54.57%
Probability of exploitation in next 30 days
99th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE