CVE-2024-38812
VMware vCenter Server Heap-Based Buffer Overflow Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
2Exploited in Wild
YesDecision
Descriptions
The vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger this vulnerability by sending a specially crafted network packet potentially leading to remote code execution.
The vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger this vulnerability by sending a specially crafted network packet potentially leading to remote code execution.
VMware vCenter Server contains a heap-based buffer overflow vulnerability in the implementation of the DCERPC protocol. This vulnerability could allow an attacker with network access to the vCenter Server to execute remote code by sending a specially crafted packet.
CVSS Scores
SSVC
- Decision:Act
Timeline
- 2024-06-19 CVE Reserved
- 2024-09-17 CVE Published
- 2024-09-19 First Exploit
- 2024-11-20 CVE Updated
- 2024-11-20 Exploited in Wild
- 2024-11-21 EPSS Updated
- 2024-12-11 KEV Due Date
CWE
- CWE-122: Heap-based Buffer Overflow
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24968 |
URL | Date | SRC |
---|---|---|
https://github.com/maybeheisenberg/CVE-2024-38812 | 2024-09-19 | |
https://github.com/groshi/CVE-2024-38812-POC-5-Hands-Private | 2024-10-28 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Broadcom Search vendor "Broadcom" | Vmware Cloud Foundation Search vendor "Broadcom" for product "Vmware Cloud Foundation" | * | - |
Affected
| ||||||
Broadcom Search vendor "Broadcom" | Vmware Vcenter Server Search vendor "Broadcom" for product "Vmware Vcenter Server" | * | - |
Affected
| ||||||
Vmware Search vendor "Vmware" | Vcenter Server Search vendor "Vmware" for product "Vcenter Server" | * | - |
Affected
|