CVE-2024-37079
published 2024-06-18CVE-2024-37079: vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may…
PriorityP193critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2026-02-13
Exploited in the wild
EPSS
22.38%
97.4th percentile
vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger this vulnerability by sending a specially crafted network packet potentially leading to remote code execution.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| vmware | cloud_foundation | >= 4.0 < 5.2 | 5.2 |
| vmware | vcenter_server | — | — |
| vmware | vcenter_server | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →CVE-2024-37079 is exploited by sending a specially crafted network packet to vCenter Server over the DCERPC protocol; monitor for anomalous DCE/RPC traffic targeting vCenter Server management interfaces ↗
- →The vulnerability is a heap-overflow in vCenter's DCE/RPC protocol implementation; inspect and alert on malformed or oversized DCE/RPC packets destined for vCenter Server ↗
- →CISA confirmed CVE-2024-37079 is actively exploited in the wild; treat any unpatched vCenter Server with external/network access as high-priority for detection and response ↗
- →Restrict and monitor network perimeter access to vSphere management components and interfaces, including storage and network components, as exploitation requires network access to vCenter Server ↗
- ·No workarounds are officially available for CVE-2024-37079; network perimeter restriction is a compensating control only, not a full mitigation ↗
- ·The vulnerability affects vCenter Server versions 7.0 and 8.0, as well as products containing vCenter including VMware vSphere and VMware Cloud Foundation ↗
- ·Exploitation requires only network access to vCenter Server — no authentication or user interaction is needed, making this a zero-interaction remote attack vector ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vulncheck9.8CRITICAL
cisa9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-qqfg-j9g4-4mfh: vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol
ghsa_unreviewed·2024-06-18
CVE-2024-37079 [CRITICAL] CWE-122 GHSA-qqfg-j9g4-4mfh: vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol
vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger this vulnerability by sending a specially crafted network packet potentially leading to remote code execution.
VulnCheck
Broadcom VMware vCenter Server Out-of-bounds Write Vulnerability
vulncheck·2024·CVSS 9.8
CVE-2024-37079 [CRITICAL] CWE-787 Broadcom VMware vCenter Server Out-of-bounds Write Vulnerability
Broadcom VMware vCenter Server Out-of-bounds Write Vulnerability
Broadcom VMware vCenter Server contains an out-of-bounds write vulnerability in the implementation of the DCERPC protocol. This could allow a malicious actor with network access to vCenter Server to send specially crafted network packets, potentially leading to remote code execution.
Affected: Broadcom VMware vCenter Server
Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Exploitation References: https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24453; https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json;
CISA
Broadcom VMware vCenter Server Out-of-bounds Write Vulnerability
cisa·2026-01-23·CVSS 9.8
CVE-2024-37079 [CRITICAL] CWE-787 Broadcom VMware vCenter Server Out-of-bounds Write Vulnerability
Vulnerability: Broadcom VMware vCenter Server Out-of-bounds Write Vulnerability
Affected: Broadcom VMware vCenter Server
Broadcom VMware vCenter Server contains an out-of-bounds write vulnerability in the implementation of the DCERPC protocol. This could allow a malicious actor with network access to vCenter Server to send specially crafted network packets, potentially leading to remote code execution.
Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Notes: https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24453 ; https://nvd.nist.gov/vuln/detail/CVE-2024-37079
Remediation Due Date: 2026-02-13
No detection rules found.
No public exploits indexed.
Bleepingcomputer
CISA: VMware ESXi flaw now exploited in ransomware attacks
blogs_bleepingcomputer·2026-02-04·CVSS 9.3
CVE-2025-22225 [CRITICAL] CISA: VMware ESXi flaw now exploited in ransomware attacks
## CISA: VMware ESXi flaw now exploited in ransomware attacks
## Sergiu Gatlan
CISA confirmed on Wednesday that ransomware gangs have begun exploiting a high-severity VMware ESXi sandbox escape vulnerability that was used in zero-day attacks since at least February 2024.
Broadcom patched this ESXi arbitrary-write vulnerability (tracked as CVE-2025-22225) almost one year ago, in March 2025, alongside a memory leak (CVE-2025-22226) and a TOCTOU flaw (CVE-2025-22224), and tagged them all as actively exploited zero-days.
"A malicious actor with privileges within the VMX process may trigger an arbitrary kernel write leading to an escape of the sandbox," Broadcom said about the CVE-2025-22225 flaw.
At the time, the company said that the three vulnerabilities affect VMware ESX products, incl
Bleepingcomputer
CISA says critical VMware RCE flaw now actively exploited
blogs_bleepingcomputer·2026-01-26·CVSS 9.8
CVE-2024-37079 [CRITICAL] CISA says critical VMware RCE flaw now actively exploited
## CISA says critical VMware RCE flaw now actively exploited
## Sergiu Gatlan
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has flagged a critical VMware vCenter Server vulnerability as actively exploited and ordered federal agencies to secure their servers within three weeks.
Patched in June 2024, this security flaw ( CVE-2024-37079 ) stems from a heap overflow weakness in the DCERPC protocol implementation of vCenter Server (a Broadcom VMware vSphere management platform that helps admins manage ESXi hosts and virtual machines).
Threat actors with network access to vCenter Server may exploit this vulnerability by sending a specially crafted network packet that can trigger remote code execution in low-complexity attacks that don't require privileges on the targeted s
Bleepingcomputer
Critical RCE bug in VMware vCenter Server now exploited in attacks
blogs_bleepingcomputer·2024-11-18·CVSS 9.8
CVE-2024-38812 [CRITICAL] Critical RCE bug in VMware vCenter Server now exploited in attacks
## Critical RCE bug in VMware vCenter Server now exploited in attacks
## Sergiu Gatlan
Broadcom warned today that attackers are now exploiting two VMware vCenter Server vulnerabilities, one of which is a critical remote code execution flaw.
TZL security researchers reported the RCE vulnerability ( CVE-2024-38812 ) during China's 2024 Matrix Cup hacking contest. It is caused by a heap overflow weakness in the vCenter's DCE/RPC protocol implementation and affects products containing vCenter, including VMware vSphere and VMware Cloud Foundation.
The other vCenter Server flaw now exploited in the wild (reported by the same researchers) is a privilege escalation flaw tracked as CVE-2024-38813 that enables attackers to escalate privileges to root with a specially crafted network packet.
"U
Bleepingcomputer
Broadcom fixes critical RCE bug in VMware vCenter Server
blogs_bleepingcomputer·2024-09-17·CVSS 9.8
CVE-2024-38812 [CRITICAL] Broadcom fixes critical RCE bug in VMware vCenter Server
## Broadcom fixes critical RCE bug in VMware vCenter Server
## Sergiu Gatlan
Broadcom has fixed a critical VMware vCenter Server vulnerability that attackers can exploit to gain remote code execution on unpatched servers via a network packet.
vCenter Server is the central management hub for VMware's vSphere suite, helping administrators manage and monitor virtualized infrastructure.
The vulnerability ( CVE-2024-38812 ), reported by TZL security researchers during China's 2024 Matrix Cup hacking contest, is caused by a heap overflow weakness in vCenter's DCE/RPC protocol implementation. It also affects products containing vCenter, including VMware vSphere and VMware Cloud Foundation.
Unauthenticated attackers can exploit it remotely in low-complexity attacks that don't require user int
Checkpoint
24th June – Threat Intelligence Report
blogs_checkpoint·2024-06-24
CVE-2024-36680 24th June – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 24th June – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 24th June, please download our Threat Intelligence Bulletin .
TOP ATTACKS AND BREACHES
The BlackSuit ransomware group has disrupted operations at CDK Global, a significant provider of IT and digital marketing solutions to the automotive industry, targeting their SaaS platforms across the United States and Canada. This incident led to significant operational disruptions, impacting vehicle sales and dealer services
Recorded Future
January 2026 CVE Landscape: 23 Critical Vulnerabilities Mark 5% Increase, APT28 Exploits Microsoft Office Zero-Day
blogs_recorded_future·CVSS 4.9
[MEDIUM] January 2026 CVE Landscape: 23 Critical Vulnerabilities Mark 5% Increase, APT28 Exploits Microsoft Office Zero-Day
# January 2026 CVE Landscape: 23 Critical Vulnerabilities Mark 5% Increase, APT28 Exploits Microsoft Office Zero-Day
January 2026 saw a modest 5% increase in high-impact vulnerabilities, with Recorded Future's Insikt Group® identifying 23 vulnerabilities requiring immediate remediation, up from 22 in December 2025. Noteworthy trends last month included Russian state-sponsored exploitation of a Microsoft Office zero-day and critical authentication bypass flaws affecting enterprise infrastructure.
What security teams need to know:
- APT28's Operation Neusploit: Russian state-sponsored actors exploited CVE-2026-21509 (Microsoft Office) via weaponized RTF files, delivering MiniDoor, PixyNetLoader, and Covenant Grunt implants
- Microsoft and SmarterTools lead concerns: These vendors accounte
https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24453https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24453https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-37079
2024-06-18
Published
2026-01-23
Added to CISA KEV
Exploited in the wild