Database/Control plane, storage & DevOps
VMware vCenter Server (DCERPC heap overflow): A heap overflow in the DCERPC implementation lets an unauthenticated
CVE-2024-37080Control plane, storage & DevOpscurated
Impact
A heap overflow in the DCERPC implementation lets an unauthenticated network attacker reach remote code execution on vCenter with a single crafted packet.
Who can reach it
Network access to vCenter Server. No authentication.
What to do
Apply the VMSA fix per Broadcom advisory 24453. vCenter appliance patch and restart. vCenter should never be reachable from tenant or general-purpose networks.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.