EXPOSURES › CVE-2024-37079
CVE-2024-37079
HIGH ⌖ ON CISA KEV · EXPLOITEDBroadcom's VMware vCenter Server exploited for RCE due to unpatched out-of-bounds write in DCERPC protocol
Broadcom's VMware vCenter Server had an unpatched out-of-bounds write vulnerability in the DCERPC protocol that was actively exploited, potentially leading to remote code execution.
Shame score — Active exploitation of a known vulnerability with potential for remote code execution.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Broadcom VMware vCenter Server contains an out-of-bounds write vulnerability in the implementation of the DCERPC protocol. This could allow a malicious actor with network access to vCenter Server to send specially crafted network packets, potentially leading to remote code execution.
| PRODUCT | STATUS |
|---|---|
| Clarity Broadcom |
Authorized |
| General Support Systems (GSS) Broadcom |
Authorized |
| Rally Broadcom |
Authorized |
| Symantec Gov Cloud Security (GCS) Broadcom |
In Process |