VMware vCenter Server RCE flaw under patch
Broadcom patched a heap overflow RCE and privilege escalation in VMware vCenter Server affecting authenticated users with network access.
Japan's IPA has issued an alert for two vulnerabilities in Broadcom's VMware vCenter Server, a widely-deployed virtualization management platform. CVE-2024-38812 is a heap-based buffer overflow in the DCE/RPC protocol implementation that allows authenticated attackers with network access to execute arbitrary code. CVE-2024-38813 is a privilege escalation flaw enabling non-admin users to gain root privileges.
Both vulnerabilities require existing access to vCenter Server but pose significant risk given the platform's central role in enterprise virtualization environments. The advisory, initially published September 18 and updated October 22, emphasizes the potential for expanding impact and urges immediate patching.
Broadcom has released patches for both flaws. Organizations running vCenter Server should apply the vendor-supplied updates immediately following the published remediation procedures. The alert does not indicate active exploitation but the combination of code execution and privilege escalation in a high-value management platform warrants prompt action.
Mentioned in this report
Source reporting: https://www.ipa.go.jp/security/security-alert/2024/alert20240918.html
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free