ZeroHour

CVE-2024-38812

KEVlarge1

Unauthenticated RCE in VMware vCenter Server via DCERPC heap overflow

CISA: VMware vCenter Server Heap-Based Buffer Overflow Vulnerability

CVSS 3.1
9.8 critical
EPSS
55%p99
Published
()
KEV added
AI analysis

VMware vCenter Server contains a heap-based buffer overflow (CWE-122/CWE-787) in its implementation of the DCERPC protocol. A remote attacker with network access to vCenter Server can trigger the flaw by sending a specially crafted network packet; no credentials, privileges, or user interaction are required (CVSS:3.1/AV:N/AC:L/PR:N/UI:N). Successful exploitation can lead to remote code execution with high impact on confidentiality, integrity, and availability of the vCenter host. Affected products are VMware vCenter Server and VMware Cloud Foundation deployments, with the exact vulnerable version ranges specified in the Broadcom/VMware advisory. The flaw is confirmed to be exploited in the wild: CISA added it to the KEV catalog on 2024-11-20, EPSS estimates a 54.6% probability of exploitation within 30 days (99th percentile), and related reporting describes PRC hackers using the BRICKSTORM backdoor in campaigns involving actively exploited VMware vCenter flaws; no public proof-of-concept is known.

What to do: Apply the patched vCenter Server / VMware Cloud Foundation releases issued by Broadcom per the vendor advisory, and because reporting indicates the fix was re-issued, verify the latest patched build is actually installed rather than an earlier, possibly incomplete one. Prioritize patching internet-facing vCenter instances and restrict network access to the vCenter management interface in the interim. Per the CISA KEV required action, apply vendor mitigations or discontinue use if mitigations are unavailable, and hunt for signs of post-exploitation (e.g., BRICKSTORM activity) given confirmed in-the-wild exploitation.

Affected
VMware (Broadcom) vCenter Serveraffected versions per the VMware/Broadcom advisory (not enumerated in the provided data)
VMware (Broadcom) VMware Cloud Foundationaffected versions per the VMware/Broadcom advisory (not enumerated in the provided data)
Estimated exposure
largeseveral thousand internet-exposed vCenter instances per public scans; on the order of 100,000+ total vCenter deployments worldwide (estimate) — vCenter is the management plane bundled with nearly every VMware vSphere environment, so total installed deployments plausibly run to hundreds of thousands, while internet-wide scans historically show only several thousand vCenter servers…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

The vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger this vulnerability by sending a specially crafted network packet potentially leading to remote code execution.

CISA Known Exploited Vulnerability
Affected
VMware vCenter Server
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
vmware
Products
cloud foundation, vcenter server
Weakness
CWE-122, CWE-787
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news