ZDI-24-882: VMware vCenter Server Appliance License Server Uncontrolled Memory Allocation Denial-of-Service Vulnerability
This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of VMware vCenter Server Appliance. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 5.3. The following CVEs are assigned: CVE-2024-37087.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-24-882?
The ZDI-24-882 vulnerability has a CVSS rating of 5.3, indicating a medium severity.
How do I fix ZDI-24-882?
To fix ZDI-24-882, you should apply the latest security patches provided by VMware for the vCenter Server Appliance.
Is authentication required to exploit ZDI-24-882?
No, authentication is not required to exploit the ZDI-24-882 vulnerability.
What type of vulnerability is ZDI-24-882?
ZDI-24-882 is a denial-of-service vulnerability that affects VMware vCenter Server Appliance installations.
Can ZDI-24-882 impact my environment?
Yes, if exploited, ZDI-24-882 can create a denial-of-service condition on affected VMware vCenter Server Appliance installations.