# VMware vCenter Server RCE flaw under patch

Published: 2024-10-21 · Severity: high
Canonical: https://vorant.io/reports/bb395f5d-a418-5793-9979-c9c94aa31b1a/vmware-vcenter-server-rce-flaw-under-patch

> Broadcom patched a heap overflow RCE and privilege escalation in VMware vCenter Server affecting authenticated users with network access.

Japan's IPA has issued an alert for two vulnerabilities in Broadcom's VMware vCenter Server, a widely-deployed virtualization management platform. CVE-2024-38812 is a heap-based buffer overflow in the DCE/RPC protocol implementation that allows authenticated attackers with network access to execute arbitrary code. CVE-2024-38813 is a privilege escalation flaw enabling non-admin users to gain root privileges.

Both vulnerabilities require existing access to vCenter Server but pose significant risk given the platform's central role in enterprise virtualization environments. The advisory, initially published September 18 and updated October 22, emphasizes the potential for expanding impact and urges immediate patching.

Broadcom has released patches for both flaws. Organizations running vCenter Server should apply the vendor-supplied updates immediately following the published remediation procedures. The alert does not indicate active exploitation but the combination of code execution and privilege escalation in a high-value management platform warrants prompt action.

## Mentioned in this report

- Vulnerabilities: CVE-2024-38812 (KEV), CVE-2024-38813 (KEV)

Source reporting: https://www.ipa.go.jp/security/security-alert/2024/alert20240918.html

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/bb395f5d-a418-5793-9979-c9c94aa31b1a/vmware-vcenter-server-rce-flaw-under-patch.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
