CyberzSOC

Publication detail
← Back to advisories & guidance

2024-100: Critical RCE Vulnerability in VMware vCenter Server ↗ source

October 22, 2024 CERT-EU Advisory

Summary

Following this, on October 21, 2024, Broadcom updated their advisory [2] with additional information about another related vulnerability tracked as CVE2024-38813. This allows an unauthenticated attacker to remotely execute arbitrary code without user interaction. via specially crafted network packets. The following products are affected: CERT-EU recommends to apply the available patches via the VMware Security Advisory [2]. The VCenter patches released on September 17, 2024 did not completely address CVE-202438812.

News Coverage

No coverage found in monitored research blogs or news feeds.

CVEs Referenced in This Publication

CVECVSSAffected
CVE-2024-38812 9.8 Critical VMware vCenter Server VMware vCenter Server contains a heap-based buffer overflow vulnerability in the implementation of the DCERPC protocol. This vulnerability could allo…
CVE-2024-38813 7.5 High VMware vCenter Server VMware vCenter contains an improper check for dropped privileges vulnerability. This vulnerability could allow an attacker with network access to the…

Extracted from the publication text. Each CVE links to its tracked detail page.

Vendors Named in This Publication

Each vendor links to its Known Exploited Vulnerabilities catalog page. Only vendors that appear in the KEV catalog are listed, either because the publication cites one of their KEV entries or because it names them directly.