Exploits

VMware Releases Patch for Critical vCenter Server RCE Vulnerability

Published  ·  2 min read

VMware has released new software updates to address a critical security flaw in vCenter Server that was previously patched but remained vulnerable. The vulnerability, tracked as CVE-2024-38812 with a CVSS score of 9.8, involves a heap-overflow vulnerability in the implementation of the DCE/RPC protocol.

According to VMware, this flaw could allow a malicious actor with network access to vCenter Server to execute remote code by sending specially crafted network packets. "A malicious actor with network access to vCenter Server may trigger this vulnerability by sending a specially crafted network packet potentially leading to remote code execution," the company, now owned by Broadcom, stated.

The flaw was originally identified by zbl and srs from Team TZL during the Matrix Cup cybersecurity competition held earlier this year in China.

"VMware by Broadcom has determined that the vCenter patches released on September 17, 2024, did not fully address CVE-2024-38812," the company added, highlighting the need for additional security updates.

Patches for the vulnerability are available in the following vCenter Server versions:

8.0 U3d

8.0 U2e

7.0 U3t

Additionally, an asynchronous patch has been provided for VMware Cloud Foundation versions 5.x, 5.1.x, and 4.x. There are no known mitigations for this vulnerability, making it critical for users to update to the latest version.

While no evidence suggests that the vulnerability has been exploited in the wild, VMware strongly advises users to update their systems to protect against potential threats.

In July 2021, China passed a law requiring vulnerabilities discovered by researchers in the country to be promptly disclosed to both the government and the affected product’s manufacturer. This has raised concerns that such vulnerabilities could be weaponized by nation-state adversaries.

Professional Services

Explore Our Cybersecurity Services

Our insights are backed by hands-on service delivery. If your business needs professional cybersecurity support, our UK-based specialists are ready to help.

© 2016 – 2026 Red Secure Tech Ltd. Registered in England and Wales — Company No: 15581067