CyberzSOC

Publication detail
← Back to advisories & guidance

2024-060: Vulnerabilities in VMware Products ↗ source

June 18, 2024 CERT-EU Advisory

Summary

Exploitation these vulnerabilities could allow a malicious actor to execute remote code or escalate privileges The vulnerabilities CVE-2024-37079 and CVE-2024-37080, both with a CVSS score of 9.8, are heap-overflow vulnerabilities in the DCERPC protocol implementation. An attacker with network access to vCenter Server can exploit these vulnerabilities to execute remote code by sending a specially crafted network packet. The vulnerability CVE-2024-37081, with a CVSS score of 7.8, is a local privilege escalation vulnerability caused by sudo misconfiguration. An authenticated local user with non-administrative privileges can exploit this vulnerability to gain root privileges. These vulnerabilities affect VMware vCenter Server 7.0 and 8.0, and VMware Cloud Foundation CERT-EU strongly recommends updating affected software to the latest versions by following the instructions given by the vendor.

News Coverage

No coverage found in monitored research blogs or news feeds.

CVEs Referenced in This Publication

CVECVSSAffected
CVE-2024-37079 9.8 Critical Broadcom VMware vCenter Server Broadcom VMware vCenter Server contains an out-of-bounds write vulnerability in the implementation of the DCERPC protocol. This could allow a malicio…
CVE-2024-37080 9.8 Critical n/a VMware vCenter Server vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter …
CVE-2024-37081 7.8 High n/a VMware vCenter Server The vCenter Server contains multiple local privilege escalation vulnerabilities due to misconfiguration of sudo. An authenticated local user with non…

Extracted from the publication text. Each CVE links to its tracked detail page.

Vendors Named in This Publication

Each vendor links to its Known Exploited Vulnerabilities catalog page. Only vendors that appear in the KEV catalog are listed, either because the publication cites one of their KEV entries or because it names them directly.