Database/Kernel, userspace & hypervisor
VMware vCenter: Heap overflow in the DCERPC implementation - unauthenticated remote code execution on vCenter
CVSS 9.8CVE-2024-37079Kernel, userspace & hypervisorcurated
Impact
Heap overflow in the DCERPC implementation - unauthenticated remote code execution on vCenter
Who can reach it
Unauthenticated network to the management plane
What to do
vCenter patch + service restart. Never expose vCenter to a tenant-reachable network segment
References
Related entries
- VMware vCenter: Heap overflow in DCERPC - unauthenticated remote code execution on vCenterCVE-2024-38812 · VMware vCenterCritical
- VMware vCenter: Privilege escalation to root on vCenter via a crafted network packetCVE-2024-38813 · VMware vCenterHigh
- VMware vCenter: Out-of-bounds write in the DCERPC implementation - unauthenticated remote code executionCVE-2023-34048 · VMware vCenterCritical
- Linux kernel (drivers/nvme/host): A discard (TRIM) request that is retried and fails again before a fresh payload isCVE-2024-41073 · Linux kernel (drivers/nvme/host)Critical
- Linux kernel mlx5_core TC connection tracking offload: Updating a connection-tracking entry allocates a replacementCVE-2024-43864 · Linux kernel mlx5_core TC connection tracking offloadCritical
- Linux kernel mlx5_core RX datapath (SHAMPO): SHAMPO can deliver completion entries with zero consumed stridesCVE-2024-44970 · Linux kernel mlx5_core RX datapath (SHAMPO)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.