VMware fixes critical vCenter Server RCE bug - again! (CVE-2024-38812)
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2024-38812 +1 in the same advisory: …38813 | Unauthenticated RCE in VMware vCenter Server via DCERPC heap overflow VMware vCenter Server contains a heap-based buffer overflow (CWE-122/CWE-787) in its implementation of the DCERPC protocol. A remote attacker with network access to vCenter Server can trigger the flaw by sending a specially crafted network packet; no credentials, privileges, or user interaction are required (CVSS:3.1/AV:N/AC:L/PR:N/UI:N). Successful exploitation can lead to remote code execution with high impact on confidentiality, integrity, and availability of the vCenter host. Affected products are VMware vCenter Server and VMware Cloud Foundation deployments, with the exact vulnerable version ranges specified in the Broadcom/VMware advisory. The flaw is confirmed to be exploited in the wild: CISA added it to the KEV catalog on 2024-11-20, EPSS estimates a 54.6% probability of exploitation within 30 days (99th percentile), and related reporting describes PRC hackers using the BRICKSTORM backdoor in campaigns involving actively exploited VMware vCenter flaws; no public proof-of-concept is known. Do: Apply the patched vCenter Server / VMware Cloud Foundation releases issued by Broadcom per the vendor advisory, and because reporting indicates the fix was re-issued, verify the latest patched build is actually installed rather than an earlier, possibly incomplete one. Prioritize patching internet-facing vCenter instances and restrict network access to the vCenter management interface in the interim. Per the CISA KEV required action, apply vendor mitigations or discontinue use if mitigations are unavailable, and hunt for signs of post-exploitation (e.g., BRICKSTORM activity) given confirmed in-the-wild exploitation. | 9.8 | 55% | KEV |
| largeseveral thousand internet-exposed vCenter instances per public scans; on the order of 100,000+ total vCenter deployments worldwide (estimate) |
Full article361 words · extracted from helpnetsecurity.com · click to collapse
Broadcom has released new patches for previously fixed vulnerabilities (CVE-2024-38812, CVE-2024-38813) in vCenter Server, one of which hasn’t been fully addressed the first time and could allow attackers to achieve remote code execution.

The vulnerabilities were privately reported by zbl & srs of team TZL – researchers who participated in the 2024 Matrix Cup in June 2024. Broadcom maintains that they are not currently aware of exploitation “in the wild.”
CVE-2024-38812 and CVE-2024-38813
VMware vCenter Server is enterprise software for managing VMware vSphere virtual environments.
CVE-2024-38812 is an unauthenticated heap-overflow vulnerability in the implementation of the DCERPC protocol that can lead to RCE and can be triggered by sending a specially crafted network packet to a vulnerable installation.
CVE-2024-38813 can be similarly triggered by attackers to escalate privileges to root.
Apply the new patches
Aside from completing the fix for CVE-2024-38812, the new updates resolve an operational issue created by the fist patch: session timeouts when accessing vCenter.
Broadcom strongly encourages customers to apply the new patches, listed in the updated advisory.
To prevent misunderstanding, the company has published a supplemental FAQ, which offers additional guidance.
CVE-2024-38812 and CVE-2024-38813 affect VMware vCenter and any products that contain vCenter, including VMware vSphere and VMware Cloud Foundation, the document spells out.
The provided patches are applicable to vCenter 7.0.3, 8.0.2, and 8.0.3, and there are asynchronous patches for VMware Cloud Foundation 4.x and 5.x.
The vulnerabilities also affect VMware vSphere 6.5 and 6.7, which are past their End of General Support dates.
“However, the last update for vSphere 6.7 contains updates to resolve this issue. There will not be an update for vSphere 6.5. If your organization has extended support please use those processes to request assistance,” the company advised.
“If there is any uncertainty about whether a system is affected, it should be presumed vulnerable, and immediate action should be taken.”
UPDATE (November 19, 2024, 06:35 a.m. ET):
Broadcom has update the supplemental FAQ document to say that “exploitation has occurred ‘in the wild’ for CVE-2024-38812 and CVE-2024-38813“.

Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2024/10/22/cve-2024-38812-cve-2024-38813-fixed-again/