CVE-2024-38812

Published Sep 17, 2024

Last updated a month ago

Overview

Description
The vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger this vulnerability by sending a specially crafted network packet potentially leading to remote code execution.
Source
security@vmware.com
NVD status
Analyzed

Risk scores

CVSS 3.1

Type
Primary
Base score
9.8
Impact score
5.9
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity
CRITICAL

Weaknesses

nvd@nist.gov
CWE-787
security@vmware.com
CWE-122

Social media

Hype score
Not currently trending
  1. #exploit 1. CVE-2024-46483: Pre-Auth Heap Overflow in Xlight SFTP server https://t.co/PBOlR0MbJb 2. CVE-2024-38812: VMWare vCenter Server DCERPC https://t.co/X88bk1DndK 3. CVE-2024-6473: Yandex Browser <24.7.1.380 DLL Hijacking https://t.co/bmugQBfCvJ

    @ksg93rd

    3 Nov 2024

    100 Impressions

    0 Retweets

    2 Likes

    2 Bookmarks

    0 Replies

    0 Quotes

  2. VMWare vCenter Server DCERPC Vulnerability CVE-2024-38812 is a complex and critical vulnerability in VMware VCenter. It’s important to understand the technical details that make this vulnerability exploitable. Learn more and stay protected 💡 https://t.co/NedPTv0cKj #SonicWall

    @loophold

    31 Oct 2024

    40 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. VMware vCenter の脆弱性 CVE-2024-38812/38813 に再パッチ:2024年9月の修正は NG https://t.co/ECjN4qzdn0 #BugBounty #China #Literacy #MatrixCup #vCenter #VMware #ZeroTrust

    @iototsecnews

    31 Oct 2024

    66 Impressions

    1 Retweet

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. Analysis of VMware vCenter heap overflow vulnerability exploited at Matrix Cup competitions in China, June 2024 (CVE-2024-38812): https://t.co/JsK3H1Cpof Another one in same code, 2023: https://t.co/jiTT2JVnqK ** Both are RCE to management console, not a hypervisor VM escape!

    @zerodaylinks

    30 Oct 2024

    5642 Impressions

    15 Retweets

    67 Likes

    28 Bookmarks

    0 Replies

    0 Quotes

  5. 🚨 🔍 Critical VMware vCenter Vulnerability: CVE-2024-38812 with CVSS 9.8 enables remote code execution. Affects multiple versions of vCenter Server. ⬇️ Deeper Dive: 🎯 Vulnerability: Remote Code Execution in VMware vCenter 🌍 Impact: CVSS Score 9.8 (Critical Severity) 🦠… http

    @ctilabs

    30 Oct 2024

    113 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. Researcher Details CVE-2024-38812 (CVSS 9.8): Critical RCE Flaw in VMware vCenter https://t.co/RxfW10wjEB https://t.co/yW1DpfdrYb

    @freedomhack101

    29 Oct 2024

    44 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  7. The CVE-2024-38812 vulnerability is a critical flaw that exposes VMware vCenter Servers to serious security risks, including remote code execution and full system compromise. #patching #vmware #vulnerabilitymanagement https://t.co/fk1L65tguE

    @SecureTeamUK

    28 Oct 2024

    76 Impressions

    0 Retweets

    2 Likes

    0 Bookmarks

    1 Reply

    1 Quote

  8. Vmware CVE-2024-38812 https://t.co/4YuqXcdBgG

    @electrocode

    28 Oct 2024

    782 Impressions

    1 Retweet

    10 Likes

    7 Bookmarks

    1 Reply

    0 Quotes

  9. PoC Published for VMWare vCenter Server RCE Vulnerability CVE-2024-38812  CybersecurityNews https://t.co/jtUCQwkr84 #SecurityInsights #CyberSecurity #InfoSec

    @iSecurity

    28 Oct 2024

    69 Impressions

    1 Retweet

    1 Like

    0 Bookmarks

    0 Replies

    1 Quote

  10. Security researchers have discovered and detailed a critical remote code execution (RCE) vulnerability in the VMware vCenter Server, identified as CVE-2024-38812. This heap-overflow flaw, which affects the server’s implementation… https://t.co/ra00SOuUAM #CyberSecurity #InfoSec

    @iSecurity

    28 Oct 2024

    60 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    1 Quote

  11. Researcher Details CVE-2024-38812 (CVSS 9.8): Critical RCE Flaw in VMware vCenter https://t.co/cWanMkgLlS

    @Dinosn

    28 Oct 2024

    4635 Impressions

    25 Retweets

    66 Likes

    15 Bookmarks

    1 Reply

    0 Quotes

  12. VWware vCenterの遠隔コード実行脆弱性CVE-2024-38812の詳細な解説が公開された。SonicWall社記事。CVE-2024-38812はCVSSスコア9.8で、DEPRPCにおけるヒープベースのバッファオーバーフロー。rpc_ss_ndr_contiguous_elt()が脆弱。 https://t.co/RCMIGOwlMi

    @__kokumoto

    28 Oct 2024

    3956 Impressions

    20 Retweets

    42 Likes

    14 Bookmarks

    1 Reply

    1 Quote

  13. Researcher Details CVE-2024-38812 (CVSS 9.8): Critical RCE Flaw in VMware vCenter Understand the impact of CVE-2024-38812, a high-risk exploit, and how to secure your #VMware vCenter Server with the necessary updates. https://t.co/yrWCVFwgzo

    @the_yellow_fall

    28 Oct 2024

    3795 Impressions

    21 Retweets

    41 Likes

    15 Bookmarks

    0 Replies

    1 Quote

  14. Happy Friday! This week, #VMware released updates for a critical flaw in vCenter Server that could enable remote code execution. Tracked as CVE-2024-38812, this vulnerability is a heap-overflow issue in the DCE/RPC protocol. 💡 Subscribe, stay informed: https://t.co/v0A3fWLBgG h

    @vali_cyber

    25 Oct 2024

    26 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  15. 𝘃𝗖𝗲𝗻𝘁𝗲𝗿 𝗦𝗲𝗿𝘃𝗲𝗿 𝗖𝗩𝗘 CVE-2024-38812 a malicious actor with network access to vCenter Server may trigger this vulnerability leading to remote code execution. There is no evidence of active exploitation and JCSC recommends applying the patch available. https://t.co/

    @CERTJersey

    24 Oct 2024

    114 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  16. VMware vCenter Server-এর দুর্বলতার (CVE-2024-38812) জন্য দ্বিতীয় নিরাপত্তা আপডেট প্রকাশ। এই বিষয়ে বিস্তারিত পড়ুন আমাদের পোস্টে: https://t.co/ZYxW8eG30C ইমেজ সোর্স: Bleeping Computer #cybersecurity #thetechacc #টেকঅ্যাক #VMware https://t.co/e3JMn8sbEG

    @TheTechAcc

    23 Oct 2024

    8 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  17. VMware has released patches for a critical vCenter Server vulnerability (CVE-2024-38812, CVSS 9.8) that could allow remote code execution. Patched versions: vCenter 8.0 U3d, 8.0 U2e, 7.0 U3t #Cybersecurity #VMware #vCenter #SecurityPatch #Infosec #RCE #CVE202438812 #Hacking htt

    @safeyourweb

    23 Oct 2024

    21 Impressions

    1 Retweet

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  18. VMware は vCenter Server RCE 脆弱性 CVE-2024-38812 に完全に対処できなかった VMware failed to fully address vCenter Server RCE flaw CVE-2024-38812 #SecurityAffairs (Oct 22) https://t.co/lPiIPQNHS4

    @foxbook

    23 Oct 2024

    213 Impressions

    0 Retweets

    3 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  19. VMware 製品の脆弱性対策について(CVE-2024-38812 等) | 情報セキュリティ | IPA 独立行政法人 情報処理推進機構 https://t.co/nrFKC9Pcxv

    @fyi787

    23 Oct 2024

    35 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  20. Another Software update in vCenter Server to patch the CVE-2024-38812. Score of 9.8 ... I guess the patch on September was not enough. As my vitamins to cure my cold was not enough, the pains comes back. Some similitude... https://t.co/natGL7MDdU

    @PhilSoupart

    22 Oct 2024

    55 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  21. إذا كنت تستخدم VMware vCenter Server قم بالتحديث بشكل عاجل، لوجود تحديث على الثغرة التي صدرت الشهر الماضي CVE-2024-38812، الثغرة تمكن المهاجم من التحكم والسيطرة عن بعد 🔴 https://t.co/HR1xT4iOIM #الامن_السيبراني

    @MAlajab

    22 Oct 2024

    1761 Impressions

    2 Retweets

    15 Likes

    9 Bookmarks

    0 Replies

    1 Quote

  22. Founders have a note: Broadcom releases patches for critical VMware vCenter Server vulnerabilities.(CVE-2024-38812-13) CVE-2024-38812(CVSS 9.8) allows remote code execution in versions 7.0, 8.0 & Cloud Foundation. Immediate patching is recommended. #cve #infosec #vm #rce

    @paramdhagia

    22 Oct 2024

    35 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  23. Founders have a note: Broadcom releases patches for critical VMware vCenter Server vulnerabilities.(CVE-2024-38812-13) CVE-2024-38812(CVSS 9.8) allows remote code execution in versions 7.0, 8.0 & Cloud Foundation. Immediate patching is recommended. #cve #infosec #vm #rc

    @paramdhagia

    22 Oct 2024

    24 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  24. Broadcom releases patches for critical VMware vCenter Server vulnerabilities (CVE-2024-38812, CVE-2024-38813). CVE-2024-38812 (CVSS 9.8) allows remote code execution in versions 7.0, 8.0 & Cloud Foundation. Immediate patching is recommended. #cve #infosec #broadcom #vm #rc

    @paramdhagia

    22 Oct 2024

    39 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  25. VMware has released another security update for CVE-2024-38812, a critical VMware vCenter Server remote code execution vulnerability that was not correctly fixed in the first patch from September 2024. [...] https://t.co/zXX9KAlltL

    @Ind_Cyber_News

    22 Oct 2024

    50 Impressions

    1 Retweet

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  26. VMware vCenter Server Vulnerabilities Let Attackers Execute Remote Code: https://t.co/2lFo9hpG1D Broadcom released critical updates for VMware vCenter Server to address vulnerabilities CVE-2024-38812 and CVE-2024-38813, which allow remote code execution and privilege escalation,

    @securityRSS

    22 Oct 2024

    37 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  27. VMware fixes critical vCenter Server RCE bug – again! (CVE-2024-38812) @MyVMUG #vulnerability #patchday https://t.co/lJHtOyr27V

    @Bhanu42140Naik

    22 Oct 2024

    43 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  28. VMware has addressed a critical vulnerability in vCenter Server, CVE-2024-38812, with a new security update. The initial patch released in September 2024 was found inadequate. Stay informed and ensure your systems are secure. Read more about the fix here: https://t.co/dHwcHSRAoR

    @trubetech

    22 Oct 2024

    23 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  29. VMware fixes critical vCenter Server RCE bug – again! (CVE-2024-38812): Broadcom has released new patches for previously fixed vulnerabilities (CVE-2024-38812, CVE-2024-38813) in vCenter Server, one of which hasn’t been fully addressed the first time and… https://t.co/rm9ZBcvsUf

    @cipherstorm

    22 Oct 2024

    52 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  30. VMware fixes critical vCenter Server RCE bug – again! (CVE-2024-38812) https://t.co/iKX7tBIbcn #HelpNetSecurity #Cybersecurity https://t.co/hHtrjkv71V

    @PoseidonTPA

    22 Oct 2024

    39 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  31. 🚨 Another critical #VMware vulnerability has been patched in the vCenter Server (CVE-2024-38812). Immediate action is required to safeguard your systems from potential exploitation. 🛡️ Ensure your environments are up to date now! 🔗 Read more: https://t.co/l6fQ0Hxon1… https://

    @socradar

    22 Oct 2024

    185 Impressions

    0 Retweets

    2 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  32. #VMware fixes critical #vCenter Server RCE bug – again! (#CVE-2024-38812) https://t.co/CDVVdv4gZ7

    @ScyScan

    22 Oct 2024

    52 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  33. VMware fixes critical vCenter Server RCE bug – again! (CVE-2024-38812): Broadcom has released new patches for previously fixed vulnerabilities (CVE-2024-38812, CVE-2024-38813) in vCenter Server, one of which hasn’t been fully addressed the first time and… https://t.co/6J6D2cdLbt

    @shah_sheikh

    22 Oct 2024

    46 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  34. #VMware fixes critical vCenter Server RCE bug – again! (#CVE-2024-38812) https://t.co/44qYhZgmc1 https://t.co/y8IQDDOrK5

    @evanderburg

    22 Oct 2024

    110 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  35. VMware failed to fully address vCenter Server RCE flaw CVE-2024-38812 https://t.co/jzMbYIPvcv

    @Dinosn

    22 Oct 2024

    4057 Impressions

    21 Retweets

    74 Likes

    11 Bookmarks

    0 Replies

    0 Quotes

  36. VMware 製品の脆弱性対策について(CVE-2024-38812 等) | 情報セキュリティ | IPA 独立行政法人 情報処理推進機構 https://t.co/5bHaTgMFvY

    @seeckjp

    22 Oct 2024

    41 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  37. VMware failed to fully address vCenter Server RCE flaw CVE-2024-38812 https://t.co/uTvB1kE3Wh #BreakingNews https://t.co/Lt0krb673S

    @evanderburg

    22 Oct 2024

    83 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  38. VMware failed to fully address vCenter Server RCE flaw CVE-2024-38812: VMware addressed a remote code execution flaw, demonstrated in a Chinese hacking contest, for the second time in two months. VMware failed to fully address a remote code execution… https://t.co/Ctaj5Uf6IU http

    @shah_sheikh

    22 Oct 2024

    37 Impressions

    1 Retweet

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  39. 更新:VMware 製品の脆弱性対策について(CVE-2024-38812 等) https://t.co/Pre9C1a81b

    @ICATalerts

    22 Oct 2024

    10893 Impressions

    22 Retweets

    45 Likes

    7 Bookmarks

    2 Replies

    5 Quotes

  40. 📌 أصدرت VMware تحديثات برمجية لسد ثغرة أمنية حرجة في vCenter Server قد تتيح تنفيذ أكواد عن بُعد. الثغرة، المعروفة برمز CVE-2024-38812 (نقاط CVSS: 9.8)، تتعلق بانتهاك تسرب الذاكرة في تنفيذ بروتوكول DCE/RPC ويمكن استغلالها من قبل جهة ضارة تتصل بالخادم. #الامن_السيبراني https://t.

    @cyberetweet

    22 Oct 2024

    32 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  41. VMware Releases vCenter Server Update to Fix Critical RCE Vulnerability VMware releases a patch for critical vCenter Server vulnerability CVE-2024-38812, urging users to update now. https://t.co/lM4sf0Fs5c https://t.co/H8bTJ2DZY5

    @rickspairdigi

    22 Oct 2024

    29 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  42. VMware has released updates for CVE-2024-38812, a critical #vulnerability in vCenter Server. With a CVSS score of 9.8, this heap-overflow flaw could allow remote code execution, fundamentally jeopardizing organizational security. Read: https://... https://t.co/FOYbeSOe8r

    @IT_news_for_all

    22 Oct 2024

    11 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  43. VMware has released updates for CVE-2024-38812, a critical #vulnerability in vCenter Server. With a CVSS score of 9.8, this heap-overflow flaw could allow remote code execution, fundamentally jeopardizing organizational security. Read: https://t.co/dsZD0lKQaA #infosec

    @TheHackersNews

    22 Oct 2024

    14578 Impressions

    89 Retweets

    189 Likes

    38 Bookmarks

    1 Reply

    3 Quotes

  44. VMware社がCVE-2024-38812をまた修正。前回9/17の修正が不完全であったため。脆弱性はDCERPCにおけるヒープベースのバッファオーバーフローで、CVSSスコア9.8。中国でのハッキングコンテストで6月に悪用されていたもの。 https://t.co/P9IDyx9Hit

    @__kokumoto

    21 Oct 2024

    2396 Impressions

    18 Retweets

    35 Likes

    5 Bookmarks

    0 Replies

    0 Quotes

  45. 🤦‍♀️🤦 "VMware by Broadcom has determined that the vCenter patches released on September 17, 2024 did not fully address CVE-2024-38812" https://t.co/AH2mH3FYTA

    @ryanaraine

    21 Oct 2024

    9258 Impressions

    9 Retweets

    15 Likes

    3 Bookmarks

    0 Replies

    2 Quotes

  46. 🆕📢 vCenter Server 7.0 Update 3t & 8.0 Update 2e is now AVAILABLE addressing CVE-2024-38812, see RN for more details 🔸70U3t 📒: https://t.co/SPRuNoPUtI 💿: https://t.co/GWBTIa2Vr6 🔹80U3e 📒: https://t.co/ZQse0zPfow 💿: https://t.co/2wUmJAfnu0

    @lamw

    21 Oct 2024

    6532 Impressions

    14 Retweets

    30 Likes

    8 Bookmarks

    2 Replies

    1 Quote

  47. まだ vSphere 6.7 を使用している方のために、vCenter Server 6.7 Update 3v がリリースされました。CVE-2024-38812 に対応したようです。塩漬け対応も少しは安心。。。いや、アップデート頑張りましょう。。。ここがエンジニアの苦しいところ。。。 https://t.co/GxcymjWnuj

    @itengineer_x76

    23 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

Configurations