CVE-2024-37080: Critical severity VMware vCenter Server vulnerability
Published Jun 18, 2024
·Updated
vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger this vulnerability by sending a specially crafted network packet potentially leading to remote code execution.
Affected Software
87 affected components
VMware vCenter Server=8.0
VMware vCenter Server=8.0-a
VMware vCenter Server=8.0-b
VMware vCenter Server=8.0-c
VMware vCenter Server=8.0-update1
VMware vCenter Server=8.0-update1a
VMware vCenter Server=8.0-update1b
VMware vCenter Server=8.0-update1c
VMware vCenter Server=8.0-update1d
VMware vCenter Server=8.0-update2
VMware vCenter Server=8.0-update2a
VMware vCenter Server=8.0-update2b
VMware vCenter Server=8.0-update2c
VMware vCenter Server=7.0
VMware vCenter Server=7.0-a
VMware vCenter Server=7.0-b
VMware vCenter Server=7.0-c
VMware vCenter Server=7.0-d
VMware vCenter Server=7.0-update1
VMware vCenter Server=7.0-update1a
VMware vCenter Server=7.0-update1c
VMware vCenter Server=7.0-update1d
VMware vCenter Server=7.0-update2
VMware vCenter Server=7.0-update2a
VMware vCenter Server=7.0-update2b
VMware vCenter Server=7.0-update2c
VMware vCenter Server=7.0-update2d
VMware vCenter Server=7.0-update3
VMware vCenter Server=7.0-update3a
VMware vCenter Server=7.0-update3c
VMware vCenter Server=7.0-update3d
VMware vCenter Server=7.0-update3e
VMware vCenter Server=7.0-update3f
VMware vCenter Server=7.0-update3g
VMware vCenter Server=7.0-update3h
VMware vCenter Server=7.0-update3i
VMware vCenter Server=7.0-update3j
VMware vCenter Server=7.0-update3k
VMware vCenter Server=7.0-update3l
VMware vCenter Server=7.0-update3m
VMware vCenter Server=7.0-update3n
VMware vCenter Server=7.0-update3o
VMware vCenter Server=7.0-update3p
All of the following
Any of the following
VMware vCenter Server=7.0
VMware vCenter Server=7.0-a
VMware vCenter Server=7.0-b
VMware vCenter Server=7.0-c
VMware vCenter Server=7.0-d
VMware vCenter Server=7.0-update1
VMware vCenter Server=7.0-update1a
VMware vCenter Server=7.0-update1c
VMware vCenter Server=7.0-update1d
VMware vCenter Server=7.0-update2
VMware vCenter Server=7.0-update2a
VMware vCenter Server=7.0-update2b
VMware vCenter Server=7.0-update2c
VMware vCenter Server=7.0-update2d
VMware vCenter Server=7.0-update3
VMware vCenter Server=7.0-update3a
VMware vCenter Server=7.0-update3c
VMware vCenter Server=7.0-update3d
VMware vCenter Server=7.0-update3e
VMware vCenter Server=7.0-update3f
VMware vCenter Server=7.0-update3g
VMware vCenter Server=7.0-update3h
VMware vCenter Server=7.0-update3i
VMware vCenter Server=7.0-update3j
VMware vCenter Server=7.0-update3k
VMware vCenter Server=7.0-update3l
VMware vCenter Server=7.0-update3m
VMware vCenter Server=7.0-update3n
VMware vCenter Server=7.0-update3o
VMware vCenter Server=7.0-update3p
VMware vCenter Server=8.0
VMware vCenter Server=8.0-a
VMware vCenter Server=8.0-b
VMware vCenter Server=8.0-c
VMware vCenter Server=8.0-update1
VMware vCenter Server=8.0-update1a
VMware vCenter Server=8.0-update1b
VMware vCenter Server=8.0-update1c
VMware vCenter Server=8.0-update1d
VMware vCenter Server=8.0-update2
VMware vCenter Server=8.0-update2a
VMware vCenter Server=8.0-update2b
VMware vCenter Server=8.0-update2c
VMware Cloud Foundation>=4.0<5.2
Remediation
Event History
Jun 18, 2024
CVE Published
via MITRE·05:43 AM
Data Sourced
via MITRE·05:43 AM
DescriptionSeverityWeakness
News Published
via The Register·06:08 AM
News Published
via The Register·06:12 AM
News Published
via BleepingComputer·06:08 PM
News Published
via BleepingComputer·06:10 PM
Frequently Asked Questions
1
What is the severity of CVE-2024-37080?
CVE-2024-37080 is considered critical due to its potential for remote code execution.
2
How do I fix CVE-2024-37080?
To fix CVE-2024-37080, update your VMware vCenter Server to the latest patched version.
3
What versions of VMware vCenter are affected by CVE-2024-37080?
CVE-2024-37080 affects VMware vCenter Server versions 7.0 and 8.0.
4
Can CVE-2024-37080 be exploited remotely?
Yes, a malicious actor with network access can exploit CVE-2024-37080 remotely.
5
What type of vulnerability is CVE-2024-37080?
CVE-2024-37080 is a heap-overflow vulnerability in the DCERPC protocol implementation.