Critical VMware vCenter Server bugs fixed (CVE-2024-38812)
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2023-34048 | Unauthenticated Out-of-Bounds Write RCE in VMware vCenter Server VMware vCenter Server contains an out-of-bounds write vulnerability (CWE-787) in its implementation of the DCERPC protocol. A remote, unauthenticated attacker with network access to vCenter Server can send crafted DCERPC traffic that corrupts memory, potentially leading to remote code execution on the vCenter appliance. Because vCenter is the central management plane for VMware vSphere environments, full compromise of it hands attackers a high-value foothold for lateral movement, consistent with the critical 9.8 CVSS score. Any organization running an affected VMware vCenter Server release is exposed (exact version ranges per VMware's advisory, including VMware Cloud Foundation deployments that bundle vCenter). Exploitation is confirmed in the wild: the flaw was added to CISA's KEV on 2024-01-22, a public PoC is available, news reports describe China-linked APT UNC3886 exploiting it as a zero-day, and EPSS estimates a 99.4% probability of exploitation within 30 days. Do: Immediately upgrade vCenter Server — and VMware Cloud Foundation deployments that bundle it — to the patched builds identified in VMware's advisory, prioritizing internet-facing instances; if patching must wait, restrict network access to the vCenter management interface as the CISA KEV required action permits. Because exploitation is confirmed in the wild including by an APT, also hunt for signs of compromise such as unexpected processes or authentication activity on vCenter hosts and managed ESXi estate. | 9.8 | 99% | KEV PoC |
| mass≈100,000+ vCenter Server deployments globally (tens of thousands directly internet-exposed per public scans, far more reachable on internal networks) | |
| CVE-2024-38812 +1 in the same advisory: …38813 | Unauthenticated RCE in VMware vCenter Server via DCERPC heap overflow VMware vCenter Server contains a heap-based buffer overflow (CWE-122/CWE-787) in its implementation of the DCERPC protocol. A remote attacker with network access to vCenter Server can trigger the flaw by sending a specially crafted network packet; no credentials, privileges, or user interaction are required (CVSS:3.1/AV:N/AC:L/PR:N/UI:N). Successful exploitation can lead to remote code execution with high impact on confidentiality, integrity, and availability of the vCenter host. Affected products are VMware vCenter Server and VMware Cloud Foundation deployments, with the exact vulnerable version ranges specified in the Broadcom/VMware advisory. The flaw is confirmed to be exploited in the wild: CISA added it to the KEV catalog on 2024-11-20, EPSS estimates a 54.6% probability of exploitation within 30 days (99th percentile), and related reporting describes PRC hackers using the BRICKSTORM backdoor in campaigns involving actively exploited VMware vCenter flaws; no public proof-of-concept is known. Do: Apply the patched vCenter Server / VMware Cloud Foundation releases issued by Broadcom per the vendor advisory, and because reporting indicates the fix was re-issued, verify the latest patched build is actually installed rather than an earlier, possibly incomplete one. Prioritize patching internet-facing vCenter instances and restrict network access to the vCenter management interface in the interim. Per the CISA KEV required action, apply vendor mitigations or discontinue use if mitigations are unavailable, and hunt for signs of post-exploitation (e.g., BRICKSTORM activity) given confirmed in-the-wild exploitation. | 9.8 | 55% | KEV |
| largeseveral thousand internet-exposed vCenter instances per public scans; on the order of 100,000+ total vCenter deployments worldwide (estimate) |
Full article366 words · extracted from helpnetsecurity.com · click to collapse
Broadcom has released fixes for two vulnerabilities affecting VMware vCenter Server that can be triggered by sending a specially crafted network packet, and could lead to remote code execution (CVE-2024-38812) or privilege escalation (CVE-2024-38813).

“Broadcom is not currently aware of exploitation ‘in the wild’,” the company says, but noted that organizations should promptly act to install one of the updated versions.
VMware has patched a similarly critical RCE flaw (CVE-2023-34048) in vCenter Server in October 2023, and Mandiant revealed a few months later that it had been exploited by a highly advanced China-backed espionage group for years.
About the vulnerabilities
VMware vCenter Server is software for managing VMware vSphere virtual environments.
CVE-2024-38812 is an unauthenticated heap-overflow vulnerability in the implementation of the DCE/RPC protocol that may potentially lead to RCE. The cause of CVE-2024-38813 has not been shared, but it may be exploited by authenticated attackers to escalate privileges to root.
They affect vCenter Server versions 8.0 and 7.0 and VMware Cloud Foundation versions 5.x and 4.x (since VMware Cloud Foundation contains vCenter).
Both vulnerabilities have been reported by researchers who participated in the 2024 Matrix Cup, a hacking competition that took place in Qingdao, China, in June.
What to do?
Admins are advised to upgrade to one of the fixed versions, since there are no alternative workarounds.
“While other mitigations may be available depending on your organization’s security posture, defense-in-depth strategies, and firewall configurations, each organization must evaluate the adequacy of these protections independently,” Broadcom states.
“The most reliable method to address these vulnerabilities is to apply the recommended patches.”
The company also reassured that updating vCenter will not affect running workloads: “vCenter is the management interface to a vSphere cluster. You will lose the use of the vSphere Client briefly during the update, and other management methods will be similarly impacted, but virtual machine and container workloads will be unaffected.”
UPDATE (November 19, 2024, 06:35 a.m. ET):
Broadcom has re-patched CVE-2024-38812 in late October, and has now confirmed that both CVE-2024-38812 and CVE-2024-38813 have been spotted being exploited in the wild.

Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2024/09/18/cve-2024-38812-cve-2024-38813/