We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2024-38812

Heap-overflow vulnerability



Assignervmware
Reserved2024-06-19
Published2024-09-17
Updated2024-11-20

Description

The vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger this vulnerability by sending a specially crafted network packet potentially leading to remote code execution.



CRITICAL: 9.8CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA Known Exploited Vulnerability

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Product status

Default status
unaffected

8.0 before 8.0 U3b
affected

7.0 before 7.0 U3s
affected

Default status
unaffected

5.x
affected

4.x
affected

References

https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24968

cve.org CVE-2024-38812

nvd.nist.gov CVE-2024-38812

Download JSON

Share this page
https://cve.threatint.com/CVE/CVE-2024-38812
Support options

Helpdesk Telegram

Subscribe to our newsletter to learn more about our work.