# VMware vCenter Server flaws enable RCE, root escalation

Published: 2024-10-21 · Severity: high · Sectors: technology, infrastructure
Canonical: https://vorant.io/reports/bb395f5d-a418-5793-9979-c9c94aa31b1a/vmware-vcenter-server-flaws-enable-rce-root-escalation

> IPA warns of a heap overflow (CVE-2024-38812) and privilege escalation flaw (CVE-2024-38813) in VMware vCenter Server that could let attackers run code or gain root.

Japan's IPA issued an advisory on two vulnerabilities affecting Broadcom's VMware vCenter Server, a widely used virtualization management platform. CVE-2024-38812 is a heap-based buffer overflow in the product's DCE/RPC protocol implementation that could allow a party with access to vCenter Server to execute arbitrary code. CVE-2024-38813 is a privilege escalation flaw that could allow a non-administrative user to elevate privileges to root.

The advisory, originally published in September 2024 and updated in October 2024, urges organizations to apply the vendor-supplied patches following Broadcom's published remediation guidance, warning that damage could expand if left unpatched. No specific exploitation activity, threat actor, or malware is described in this notice; it is a vendor-patch awareness alert rather than a report of active in-the-wild attacks.

Given vCenter Server's central role in managing virtualized infrastructure across enterprise environments, unpatched instances represent a significant risk surface — successful exploitation chaining both flaws could grant an attacker full administrative control over a virtualization environment. Organizations running affected vCenter Server versions should prioritize patching per Broadcom's advisory.

## Mentioned in this report

- Vulnerabilities: CVE-2024-38812 (KEV), CVE-2024-38813 (KEV)

Source reporting: https://www.ipa.go.jp/security/security-alert/2024/alert20240918.html

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/bb395f5d-a418-5793-9979-c9c94aa31b1a/vmware-vcenter-server-flaws-enable-rce-root-escalation.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
