EXPOSURES › CVE-2024-38812
CVE-2024-38812
HIGH ⌖ ON CISA KEV · EXPLOITEDVMware vCenter Server exploited via heap-based buffer overflow enabling remote code execution.
A heap-based buffer overflow in VMware vCenter Server's DCERPC protocol allows remote attackers to execute arbitrary code, directly violating CMMC/NIST 800-171 remote access controls. DIB orgs must immediately patch vCenter instances and audit network segmentation to prevent unauthorized code execution on critical infrastructure.
Shame score — A known vulnerability in a widely deployed critical infrastructure product that enables remote code execution, though not zero-day.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
VMware vCenter Server contains a heap-based buffer overflow vulnerability in the implementation of the DCERPC protocol. This vulnerability could allow an attacker with network access to the vCenter Server to execute remote code by sending a specially crafted packet.
| PRODUCT | STATUS |
|---|---|
| VMware Government Services (VGS) VMware, Inc. |
Authorized |
| Workspace ONE VMware, Inc. |
Authorized |