← Back to browse · API

CVE-2024-37080

Severity
CRITICAL
CVSS
9.8
EPSS
0.12478
Risk score
43.57
CISA KEV
No
PoC
No
Published
2024-06-18
Modified
2026-01-24
First seen
2026-08-07
Aliases
EUVD-2024-36413, GHSA-MW3W-F2GC-G47M
Products
VMware:VMware Cloud Foundation 4.x, VMware:VMware Cloud Foundation 5.x, n/a:VMware vCenter Server 7.0 <7.0 U3r, n/a:VMware vCenter Server 8.0 <8.0 U1e, n/a:VMware vCenter Server 8.0 <8.0 U2d
Sources
euvd EUVD-2024-36413

Description

vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger this vulnerability by sending a specially crafted network packet potentially leading to remote code execution.

References