CVE-2024-38812: VMware vCenter Server Heap-Based Buffer Overflow Vulnerability
The vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger this vulnerability by sending a specially crafted network packet potentially leading to remote code execution.
Other sources
VMware vCenter Server contains a heap-based buffer overflow vulnerability in the implementation of the DCERPC protocol. This vulnerability could allow an attacker with network access to the vCenter Server to execute remote code by sending a specially crafted packet.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
VMware vCenterfrom your environment.Discontinue use of or uninstall VMware vCenter Server if vendor mitigations are unavailable.
- Compensating control
Apply vendor-provided mitigations per VMware's instructions to mitigate the DCERPC heap-overflow vulnerability in vCenter Server.
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2024-38812?
CVE-2024-38812 has been classified as critical due to its potential for remote code execution.
How do I fix CVE-2024-38812?
To fix CVE-2024-38812, apply the latest security patch provided by VMware for vCenter Server.
Who is affected by CVE-2024-38812?
CVE-2024-38812 affects VMware vCenter Server versions 7.0 and 8.0, including various updates.
What kind of vulnerability is CVE-2024-38812?
CVE-2024-38812 is a heap-overflow vulnerability in the DCERPC protocol implementation.
Can CVE-2024-38812 be exploited remotely?
Yes, a malicious actor with network access can exploit CVE-2024-38812 by sending a specially crafted network packet.