← Back to browse · API

CVE-2024-37079

Severity
CRITICAL
CVSS
9.8
EPSS
0.22377
Risk score
72.03
CISA KEV
Yes
PoC
No
Published
2024-06-18
Modified
2026-01-24
First seen
2026-08-07
Aliases
EUVD-2024-36412, GHSA-QQFG-J9G4-4MFH
Products
Broadcom:VMware vCenter Server, VMware:VMware Cloud Foundation 4.x, VMware:VMware Cloud Foundation 5.x, n/a:VMware vCenter Server 7.0 <7.0 U3r, n/a:VMware vCenter Server 8.0 <8.0 U1e, n/a:VMware vCenter Server 8.0 <8.0 U2d
Sources
euvd EUVD-2024-36412
cisa.gov CVE-2024-37079

Description

vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger this vulnerability by sending a specially crafted network packet potentially leading to remote code execution.

References