Database/Kernel, userspace & hypervisor
VMware vCenter: Heap overflow in DCERPC - unauthenticated remote code execution on vCenter
CVSS 9.8CVE-2024-38812Kernel, userspace & hypervisorKnown exploitedcurated
Impact
Heap overflow in DCERPC - unauthenticated remote code execution on vCenter [KEV]
Who can reach it
Unauthenticated network to the management plane
What to do
vCenter patch + service restart; the first patch was incomplete, so verify the build number rather than trusting the advisory date
References
Related entries
- VMware vCenter: Privilege escalation to root on vCenter via a crafted network packetCVE-2024-38813 · VMware vCenterHigh
- VMware vCenter: Out-of-bounds write in the DCERPC implementation - unauthenticated remote code executionCVE-2023-34048 · VMware vCenterCritical
- VMware vCenter: Heap overflow in the DCERPC implementation - unauthenticated remote code execution on vCenterCVE-2024-37079 · VMware vCenterCritical
- Linux kernel (drivers/nvme/host): A discard (TRIM) request that is retried and fails again before a fresh payload isCVE-2024-41073 · Linux kernel (drivers/nvme/host)Critical
- Linux kernel mlx5_core TC connection tracking offload: Updating a connection-tracking entry allocates a replacementCVE-2024-43864 · Linux kernel mlx5_core TC connection tracking offloadCritical
- Linux kernel mlx5_core RX datapath (SHAMPO): SHAMPO can deliver completion entries with zero consumed stridesCVE-2024-44970 · Linux kernel mlx5_core RX datapath (SHAMPO)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.