VMware Discloses Critical Vulnerabilities, Urges Immediate Remediation
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2024-37079 | Out-of-bounds Write in Broadcom VMware vCenter Server DCERPC Enables RCE CVE-2024-37079 is an out-of-bounds write (CWE-787) in the implementation of the DCERPC protocol in VMware vCenter Server, Broadcom's management platform for vSphere virtualization environments. A malicious actor with network access to a vulnerable vCenter Server can trigger the flaw by sending specially crafted network packets, corrupting memory and potentially achieving remote code execution on the server. Successful exploitation would give an attacker control of a central management component, typically a strong foothold for lateral movement across the virtualized estate, though ransomware use is currently listed as unknown. Any organization running affected vCenter Server builds is exposed, with risk highest where the management interface is reachable from untrusted networks or the internet. CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2026-01-23, confirming exploitation in the wild; no public PoC is known, CVSS was not yet scored in the source data, and the high EPSS score (22.4%, 98th percentile) signals elevated near-term exploitation risk. Do: Upgrade vCenter Server to a patched release per Broadcom's 2024 advisory (VMSA-2024-0012) without delay, since exploitation is confirmed in the wild and CISA BOD 22-01 requires federal agencies to apply vendor mitigations or discontinue use per the KEV deadline. Inventory your vCenter builds and compare them against the advisory's affected ranges; installations already patched for the 2024 DCERPC fixes are protected. Until patching completes, restrict network access to vCenter management interfaces (firewall allowlisting or VPN) and prioritize any internet-exposed instances. | 9.8 | 22% | KEV |
| large≈tens of thousands of internet-exposed vCenter instances, with total deployments plausibly in the hundreds of thousands | |
| CVE-2024-37080 +1 in the same advisory: …37081 | vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger this vulnerability by sending a specially crafted network packet potentially leading to remote code execution. NVD description · AI analysis pending | 9.8 group max | 12% |
| — |
Full article433 words · extracted from infosecurity-magazine.com · click to collapse
VMware has disclosed critical vulnerabilities impacting its VMware vSphere and VMware Cloud Foundation products, urging customers to immediately install updates containing patches.
The issues are in the VMware vCenter Server, which is present in the affected products.
In a critical security advisory published on June 17, 2024, the cloud computing firm highlighted three CVEs with severity scores ranging from 7.8-9.8.
The vulnerabilities are memory management and corruption flaw, potentially leading to remote code execution.
- Multiple heap-overflow vulnerabilities: CVE-2024-37079 and CVE-2024-37080 relate to multiple heap-overflow vulnerabilities in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger these vulnerabilities by sending a specially crafted network packet potentially leading to remote code execution. These issues have been given a CVSS score of 9.8.
- Multiple local privilege escalation vulnerabilities: CVE-2024-37081 relates to multiple local privilege escalation vulnerabilities due to misconfiguration of sudo. An authenticated local user with non-administrative privileges may exploit these issues to elevate privileges to root on vCenter Server Appliance. These issues have been given a CVSS score of 7.8.
VMWare Customers Urged to Take Action
While VMware is not currently aware of exploitation of the vulnerabilities in the wild, it is recommending that customers take immediate action to address the issues, given the severity.
Patches have been applied in the following updates that are available to customers:
vCenter Server
Version 8.0 U2d is available for customers running v 8.0 of VMware’s vCenter Server. This version has fixes for CVE-2024-37079, CVE-2024-37080 and CVE-2024-37081.
8.0 U1e is also available for v 8.0. This has patches for CVE-2024-37079 and CVE-2024-37080.
For customers using vCenter Server v 7.0, v 7.0 U3r is available which contains fixes for CVE-2024-37079, CVE-2024-37080, CVE-2024-37081.
Cloud Foundation
Version KB88287 is available for customers using v 4.x and 5.x of VMware’s Cloud Foundation, and has fixes for CVE-2024-37079, CVE-2024-37080 and CVE-2024-37081.
Workarounds
VMware said it investigated in-product workarounds for the vulnerabilities, but none were determined to be viable.
The company stated: “There may be other mitigations and compensating controls available in your organization, depending on your security posture, defense-in-depth strategies, and configurations of perimeter firewalls and appliance firewalls. All organizations must decide for themselves whether to rely on those protections.”
VMware has not evaluated whether vSphere product versions 6.5 or 6.7 have the vulnerabilities as they are past their End of General Support dates.
VMware has thanked Hao Zheng and Zibo Li from TianGong Team of Legendsec at Qi'anxin Group for responsibly reporting the issues in CVE-2024-37079 and CVE-2024-37080 to them, and Matei "Mal" Badanoiu for reporting the issues in CVE-2024-37081.
Image credit: Mehaniq / Shutterstock.com
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/vmware-critical-vulnerabilities/