Database/Control plane, storage & DevOps
VMware vCenter Server (DCERPC heap overflow): A heap overflow in the DCERPC implementation lets an unauthenticated
CVSS 9.8CVE-2024-37080Control plane, storage & DevOpscurated
Impact
A heap overflow in the DCERPC implementation lets an unauthenticated network attacker reach remote code execution on vCenter with a single crafted packet.
Who can reach it
Network access to vCenter Server. No authentication.
What to do
Apply the VMSA fix per Broadcom advisory 24453. vCenter appliance patch and restart. vCenter should never be reachable from tenant or general-purpose networks.
References
Related entries
- Terraform (go-getter): Argument injection when go-getter shells out to Git for remote branch discoveryCVE-2024-3817 · Terraform (go-getter)Critical
- Veeam Backup & Replication: Deserialization of untrusted dataCVE-2024-40711 · Veeam Backup & ReplicationCritical
- Fluent Bit: "Linguistic Lumberjack" - memory corruption parsing trace requests in the embedded HTTP serverCVE-2024-4323 · Fluent BitCritical
- Fortinet FortiManager: "FortiJump" - missing authentication in fgfmdCVE-2024-47575 · Fortinet FortiManagerCritical
- GitHub Enterprise Server: Forged SAML response with encrypted assertions enabledCVE-2024-4985 · GitHub Enterprise ServerCritical
- Linux NFS server (nfsd, laundromat vs free_stateid race): A race between the delegation laundromat and a client-issuedCVE-2024-50106 · Linux NFS server (nfsd, laundromat vs free_stateid race)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.