← Back to browse · API

CVE-2024-38812

Severity
CRITICAL
CVSS
9.8
EPSS
0.54571
Risk score
83.3
CISA KEV
Yes
PoC
No
Published
2024-11-20
Modified
2024-11-20
First seen
2026-08-07
Aliases
EUVD-2024-37703, GHSA-72Q3-GVH6-6M6W
Products
VMware:VMware Cloud Foundation 4.x, VMware:VMware Cloud Foundation 5.x, VMware:vCenter Server, n/a:VMware vCenter Server 7.0 <7.0 U3s, n/a:VMware vCenter Server 8.0 <8.0 U3b
Sources
euvd EUVD-2024-37703
cisa.gov CVE-2024-38812

Description

VMware vCenter Server contains a heap-based buffer overflow vulnerability in the implementation of the DCERPC protocol. This vulnerability could allow an attacker with network access to the vCenter Server to execute remote code by sending a specially crafted packet.

References