GPU VulnDB

Database/Control plane, storage & DevOps

VMware vCenter Server (DCERPC heap overflow): A heap overflow in the DCERPC implementation lets an unauthenticated

CVE-2024-37080Control plane, storage & DevOpscurated

Impact

A heap overflow in the DCERPC implementation lets an unauthenticated network attacker reach remote code execution on vCenter with a single crafted packet.

Who can reach it

Network access to vCenter Server. No authentication.

What to do

Apply the VMSA fix per Broadcom advisory 24453. vCenter appliance patch and restart. vCenter should never be reachable from tenant or general-purpose networks.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.