CVE-2024-38812
published 2024-09-17CVE-2024-38812: The vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server…
PriorityP195critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2024-12-11
Exploited in the wild
EPSS
54.14%
98.9th percentile
The vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger this vulnerability by sending a specially crafted network packet potentially leading to remote code execution.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| vmware | cloud_foundation | >= 4.0 < 5.2 | 5.2 |
| vmware | vcenter_server | — | — |
| vmware | vcenter_server | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Detect exploitation attempts by monitoring for specially crafted network packets targeting the DCE/RPC protocol implementation on vCenter Server ↗
- →Monitor vCenter Server network interfaces for anomalous DCE/RPC traffic, particularly from unauthenticated sources — exploitation requires no authentication and no user interaction ↗
- →Restrict and monitor network perimeter access to vSphere management components and interfaces, including storage and network components, as a compensating control ↗
- →CVE-2024-38812 is confirmed exploited in the wild — treat any unpatched vCenter Server exposure as actively targeted; apply patches for vCenter Server 8.0 U3d, 8.0 U2e, and 7.0 U3t immediately ↗
- →Note that the initial September 17, 2024 patches did NOT fully remediate CVE-2024-38812; systems patched only with the first release remain vulnerable — verify patch version is 8.0 U3d, 8.0 U2e, or 7.0 U3t ↗
- →vSphere 6.5 and 6.7 are confirmed impacted but will NOT receive patches — treat these versions as permanently vulnerable and prioritize isolation or decommission ↗
- ·No workarounds are available for CVE-2024-38812; the only remediation is applying the latest vendor patches ↗
- ·CISA KEV remediation deadline was 2024-12-11; any vCenter Server still unpatched beyond this date is in violation of KEV requirements ↗
- ·The vulnerability is a heap-based buffer overflow in the DCERPC protocol implementation — CVSS v3.1 score is 9.8 (Critical) ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vulncheck9.8CRITICAL
cisa9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA
VMware vCenter Server Heap-Based Buffer Overflow Vulnerability
cisa·2024-11-20·CVSS 9.8
CVE-2024-38812 [CRITICAL] CWE-122 VMware vCenter Server Heap-Based Buffer Overflow Vulnerability
Vulnerability: VMware vCenter Server Heap-Based Buffer Overflow Vulnerability
Affected: VMware vCenter Server
VMware vCenter Server contains a heap-based buffer overflow vulnerability in the implementation of the DCERPC protocol. This vulnerability could allow an attacker with network access to the vCenter Server to execute remote code by sending a specially crafted packet.
Required Action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Notes: https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24968 ; https://nvd.nist.gov/vuln/detail/CVE-2024-38812
Remediation Due Date: 2024-12-11
GHSA
GHSA-72q3-gvh6-6m6w: The vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol
ghsa_unreviewed·2024-09-17
CVE-2024-38812 [CRITICAL] CWE-122 GHSA-72q3-gvh6-6m6w: The vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol
The vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger this vulnerability by sending a specially crafted network packet potentially leading to remote code execution.
VulnCheck
VMware vCenter Server Heap-Based Buffer Overflow Vulnerability
vulncheck·2024·CVSS 9.8
CVE-2024-38812 [CRITICAL] CWE-122 VMware vCenter Server Heap-Based Buffer Overflow Vulnerability
VMware vCenter Server Heap-Based Buffer Overflow Vulnerability
VMware vCenter Server contains a heap-based buffer overflow vulnerability in the implementation of the DCERPC protocol. This vulnerability could allow an attacker with network access to the vCenter Server to execute remote code by sending a specially crafted packet.
Affected: VMware vCenter Server
Required Action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Exploitation References: https://attackerkb.com/topics/pDMaaTA6Th/cve-2024-38812#exploited-in-the-wild_c8779024-ade3-4079-87ed-8deaab4671af; https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24968; https://www.cisa.gov/sites/default/files/feeds/known_ex
No detection rules found.
No public exploits indexed.
Bleepingcomputer
Broadcom fixes high-severity VMware NSX bugs reported by NSA
blogs_bleepingcomputer·2025-09-30·CVSS 9.3
CVE-2025-41251 [CRITICAL] Broadcom fixes high-severity VMware NSX bugs reported by NSA
## Broadcom fixes high-severity VMware NSX bugs reported by NSA
## Sergiu Gatlan
Broadcom has released security updates to patch two high-severity VMware NSX vulnerabilities reported by the U.S. National Security Agency (NSA).
VMware NSX is a networking virtualization solution within VMware Cloud Foundation that enables administrators to deploy traditional and modern applications in private/hybrid clouds.
The first security flaw reported by the NSA, tracked as CVE-2025-41251 , is due to a weakness in the password recovery mechanism that can let unauthenticated attackers enumerate valid usernames, which could later be used in brute-force attacks.
The second one ( CVE-2025-41252 ) is a username enumeration vulnerability that unauthenticated threat actors can also exploit to enumerate va
Qualys
Inside LockBit: Defense Lessons from the Leaked LockBit Negotiations | Qualys
blogs_qualys·2025-05-08
Inside LockBit: Defense Lessons from the Leaked LockBit Negotiations | Qualys
#### Table of Contents
- Who is LockBit? How it Evolved and Operates
- Monero: The Coin of the Realm
- Patch or Mitigate Now: Critical CVEs Exploited by LockBit
- Beyond Traditional Endpoints: Other Compromised Systems
- Initial Access and Deployment
- Conclusion
The LockBit ransomware gang recently suffered a significant data breach. Their dark web affiliate panels were defaced with the message “Don’t do crime CRIME IS BAD xoxo from Prague,” linking to a MySQL database dump. This archive contains a SQL file from LockBit’s affiliate panel database that includes twenty tables, notably including a ‘btc_addresses’ table with 59,975 unique bitcoin addresses and a ‘chats’ table containing over 4,400 victim negotiation messages from December 2024 to the end of April 2025.
This blog post will
Qualys
Inside LockBit: Defense Lessons from the Leaked LockBit Negotiations
blogs_qualys·2025-05-08
Inside LockBit: Defense Lessons from the Leaked LockBit Negotiations
## Table of Contents
Who is LockBit? How it Evolved and Operates
Monero: The Coin of the Realm
Patch or Mitigate Now: Critical CVEs Exploited by LockBit
Beyond Traditional Endpoints: Other Compromised Systems
Initial Access and Deployment
Conclusion
The LockBit ransomware gang recently suffered a significant data breach. Their dark web affiliate panels were defaced with the message “Don’t do crime CRIME IS BAD xoxo from Prague,” linking to a MySQL database dump. This archive contains a SQL file from LockBit’s affiliate panel database that includes twenty tables, notably including a ‘btc_addresses’ table with 59,975 unique bitcoin addresses and a ‘chats’ table containing over 4,400 victim negotiation messages from December 2024 to the end of April 2025.
This blog post will leverage
Bleepingcomputer
Broadcom fixes three VMware zero-days exploited in attacks
blogs_bleepingcomputer·2025-03-04·CVSS 9.8
CVE-2025-22224 [CRITICAL] Broadcom fixes three VMware zero-days exploited in attacks
## Broadcom fixes three VMware zero-days exploited in attacks
## Sergiu Gatlan
"This is a situation where an attacker who has already compromised a virtual machine's guest OS and gained privileged access (administrator or root) could move into the hypervisor itself," the company explained today. "Broadcom has information to suggest that exploitation of these issues has occurred 'in the wild'."
Broadcom says CVE-2025-22224 is a critical-severity VCMI heap overflow vulnerability that enables local attackers with administrative privileges on the targeted VM to execute code as the VMX process running on the host.
CVE-2025-22225 is an ESXi arbitrary write vulnerability that allows the VMX process to trigger arbitrary kernel writes, leading to a sandbox escape, while CVE-2025-22226 is descri
Tenable
Cybersecurity Snapshot: CISA Calls for Stamping Out Buffer Overflow Vulnerabilities, as Europol Tells Banks To Prep For Quantum Threat
blogs_tenable·2025-02-14
Cybersecurity Snapshot: CISA Calls for Stamping Out Buffer Overflow Vulnerabilities, as Europol Tells Banks To Prep For Quantum Threat
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Bleepingcomputer
Critical RCE bug in VMware vCenter Server now exploited in attacks
blogs_bleepingcomputer·2024-11-18·CVSS 9.8
CVE-2024-38812 [CRITICAL] Critical RCE bug in VMware vCenter Server now exploited in attacks
## Critical RCE bug in VMware vCenter Server now exploited in attacks
## Sergiu Gatlan
Broadcom warned today that attackers are now exploiting two VMware vCenter Server vulnerabilities, one of which is a critical remote code execution flaw.
TZL security researchers reported the RCE vulnerability ( CVE-2024-38812 ) during China's 2024 Matrix Cup hacking contest. It is caused by a heap overflow weakness in the vCenter's DCE/RPC protocol implementation and affects products containing vCenter, including VMware vSphere and VMware Cloud Foundation.
The other vCenter Server flaw now exploited in the wild (reported by the same researchers) is a privilege escalation flaw tracked as CVE-2024-38813 that enables attackers to escalate privileges to root with a specially crafted network packet.
"U
Checkpoint
28th October – Threat Intelligence Report
blogs_checkpoint·2024-10-28
CVE-2024-20481 28th October – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 28th October – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 28th October, please download our Threat Intelligence Bulletin .
TOP ATTACKS AND BREACHES
Grupo Aeroportuario del Centro Norte (OMA), operator of 13 airports across Mexico, was hacked by the RansomHub ransomware gang, who threatened to leak 3TB of stolen data unless a ransom is paid. The attack disrupted terminal information screens and forced OMA to activate backup systems, with no reported material adverse e
Bleepingcomputer
VMware fixes bad patch for critical vCenter Server RCE flaw
blogs_bleepingcomputer·2024-10-22·CVSS 9.8
CVE-2024-38812 [CRITICAL] VMware fixes bad patch for critical vCenter Server RCE flaw
## VMware fixes bad patch for critical vCenter Server RCE flaw
## Bill Toulas
VMware has released another security update for CVE-2024-38812, a critical VMware vCenter Server remote code execution vulnerability that was not correctly fixed in the first patch from September 2024.
The flaw is rated critical (CVSS v3.1 score: 9.8) and stems from a heap overflow weakness in vCenter's DCE/RPC protocol implementation, impacting the vCenter Server and any products incorporating it, such as vSphere and Cloud Foundation.
The flaw does not require user interaction for exploitation, as remote code execution is triggered when a specially crafted network packet is received.
The vulnerability was discovered and used by TZL security researchers during China's 2024 Matrix Cup hacking contest. The res
Checkpoint
23rd September – Threat Intelligence Report
blogs_checkpoint·2024-09-23
CVE-2024-8897 23rd September – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 23rd September – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 23rd September, please download our Threat Intelligence Bulletin .
TOP ATTACKS AND BREACHES
Medusa ransomware gang has claimed responsibility for an attack on the Providence Public School District (PPSD) in Rhode Island. The school district is still grappling with ongoing internet outages since September 11, impacting over 20,000 students across 37 schools. While the district has contacted law enforcement an
Bleepingcomputer
Broadcom fixes critical RCE bug in VMware vCenter Server
blogs_bleepingcomputer·2024-09-17·CVSS 9.8
CVE-2024-38812 [CRITICAL] Broadcom fixes critical RCE bug in VMware vCenter Server
## Broadcom fixes critical RCE bug in VMware vCenter Server
## Sergiu Gatlan
Broadcom has fixed a critical VMware vCenter Server vulnerability that attackers can exploit to gain remote code execution on unpatched servers via a network packet.
vCenter Server is the central management hub for VMware's vSphere suite, helping administrators manage and monitor virtualized infrastructure.
The vulnerability ( CVE-2024-38812 ), reported by TZL security researchers during China's 2024 Matrix Cup hacking contest, is caused by a heap overflow weakness in vCenter's DCE/RPC protocol implementation. It also affects products containing vCenter, including VMware vSphere and VMware Cloud Foundation.
Unauthenticated attackers can exploit it remotely in low-complexity attacks that don't require user int
Crowdstrike
Unveiling WARP PANDA: A New Sophisticated China-Nexus Adversary
blogs_crowdstrike·CVSS 7.5
CVE-2026-20929 [HIGH] Unveiling WARP PANDA: A New Sophisticated China-Nexus Adversary
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
Video Highlights the 4 Key Steps to Successful Incident Response Dec 02, 2019
Helping Non-Security Stakeholders Understand ATT&CK in 10 Minutes or Less [VI
2024-09-17
Published
2024-11-20
Added to CISA KEV
Exploited in the wild