cbcvebase.
CVE-2024-37079
published 2024-06-18

CVE-2024-37079: vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may…

PriorityP193critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2026-02-13
Exploited in the wild
EPSS
22.38%
97.4th percentile
vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger this vulnerability by sending a specially crafted network packet potentially leading to remote code execution.

Affected

3 ranges
VendorProductVersion rangeFixed in
vmwarecloud_foundation>= 4.0 < 5.25.2
vmwarevcenter_server
vmwarevcenter_server

Detection & IOCsextracted from sources · hover to see the quote

  • CVE-2024-37079 is exploited by sending a specially crafted network packet to vCenter Server over the DCERPC protocol; monitor for anomalous DCE/RPC traffic targeting vCenter Server management interfaces
  • The vulnerability is a heap-overflow in vCenter's DCE/RPC protocol implementation; inspect and alert on malformed or oversized DCE/RPC packets destined for vCenter Server
  • CISA confirmed CVE-2024-37079 is actively exploited in the wild; treat any unpatched vCenter Server with external/network access as high-priority for detection and response
  • Restrict and monitor network perimeter access to vSphere management components and interfaces, including storage and network components, as exploitation requires network access to vCenter Server
  • ·No workarounds are officially available for CVE-2024-37079; network perimeter restriction is a compensating control only, not a full mitigation
  • ·The vulnerability affects vCenter Server versions 7.0 and 8.0, as well as products containing vCenter including VMware vSphere and VMware Cloud Foundation
  • ·Exploitation requires only network access to vCenter Server — no authentication or user interaction is needed, making this a zero-interaction remote attack vector

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vulncheck9.8CRITICAL
cisa9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.