PT-2024-6262 · Vmware · Vmware Vcenter Server+1

+1

·

CVE-2024-38812

·

Published

2024-09-17

·

Updated

2026-09-05

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions VMware vCenter Server (affected versions not specified)
Description A heap-overflow memory error exists in the implementation of the DCERPC protocol. An unauthenticated malicious actor with network access may trigger this issue by sending a specially crafted network packet, potentially leading to remote code execution on the server. Over 45,000 potentially affected instances have been identified via network scanning.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

DoS

Memory Corruption

Heap Based Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-07209
CVE-2024-38812

Affected Products

Vmware Vcenter
Vmware Vcenter Server