logo

VMware by Broadcom warns of two critical vCenter flaws, plus a nasty sudo bug

ID: 1304e0e7-362d-5351-900f-41349c4a5cfa

STIX ID: report--1304e0e7-362d-5351-900f-41349c4a5cfa

Feed Name: The Register (Security)

Threat Score
75/100

Date Published: 2024-06-18

Date Updated: 2026-04-26

Author: Simon Sharwood

...
...

VMware/Broadcom disclosed two critical heap-overflow vulnerabilities in vCenter Server's DCE/RPC implementation (CVE-2024-37079 and CVE-2024-37080, CVSS 9.8) that could enable remote code execution, plus an important local privilege escalation (CVE-2024-37081) related to sudo misconfiguration; patches are available and the vendor reports no known in-the-wild exploitation, though unsupported older vSphere releases may still be vulnerable.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.