CVE-2024-37079

9.5 CISA KEV

Broadcom · VMware vCenter Server

Broadcom VMware vCenter Server contains a heap-overflow vulnerability in the DCERPC protocol implementation, allowing an unauthenticated attacker to achieve remote code execution.

Executive summary

This critical heap-overflow vulnerability in VMware vCenter Server is currently being exploited in the wild and allows unauthenticated attackers to achieve remote code execution.

Vulnerability

This is a heap-overflow vulnerability located in the DCERPC protocol implementation. An unauthenticated attacker with network access to the vCenter Server can trigger this flaw by sending a specially crafted network packet to achieve remote code execution.

Business impact

The vulnerability carries a CVSS score of 9.5, reflecting its potential for total system compromise. Successful exploitation grants an attacker complete control over the virtualization management environment, which can lead to unauthorized access to all hosted virtual machines, data exfiltration, and severe operational disruption. Given its inclusion in the CISA Known Exploited Vulnerabilities catalog, the risk of targeted attacks against enterprise infrastructure is extreme.

Remediation

Immediate Action: Update VMware vCenter Server to versions 8.0 U2d, 8.0 U1e, or 7.0 U3r immediately. For VMware Cloud Foundation 4.x and 5.x environments, apply the specific guidance outlined in KB88287.

Proactive Monitoring: Monitor network traffic for anomalous DCERPC requests directed at vCenter management interfaces. Review system logs for unexpected process execution or service restarts that may indicate exploitation attempts.

Compensating Controls: Implement strict network segmentation to limit access to the vCenter management interface to authorized administrative segments only. Utilize a Web Application Firewall or network-based intrusion detection system to filter malicious traffic patterns targeting the DCERPC service.

Exploitation status

Public Exploit Available: Yes, a proof-of-concept exists on GitHub.

Analyst recommendation

Due to the critical severity of this vulnerability and confirmed active exploitation in the wild, organizations must prioritize patching as the highest priority. If immediate patching is not feasible, ensure the vCenter management interface is not exposed to the public internet and restrict internal access to the absolute minimum necessary. Delaying remediation poses an unacceptable risk of full environment compromise.

More Broadcom CVEs

Sources