← back
CVE-2024-37079

CVE-2024-37079

CVSS 9.8 CRITICALEPSS 22.4%● KEVCWE-787
In short

vCenter Server has a memory overflow bug in its DCERPC protocol handler. An attacker on the network can send a specially crafted packet to execute malicious code on the server without needing credentials.

Technical detail

Heap-overflow vulnerability in DCERPC protocol implementation allows unauthenticated remote code execution. Attack vector is network-based requiring only network connectivity; no prior authentication or user interaction needed. Successful exploitation grants complete server compromise with CRITICAL impact.

Summary generated and translated by AI from the official description.
vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger this vulnerability by sending a specially crafted network packet potentially leading to remote code execution.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →