logo

Critical 9.8-rated VMware vCenter RCE bug exploited after patch fumble

ID: 1aa2b4fa-360c-5bd4-81da-302f3c4a63a2

STIX ID: report--1aa2b4fa-360c-5bd4-81da-302f3c4a63a2

Feed Name: The Register (Security)

Threat Score
85/100

Date Published: 2024-11-18

Date Updated: 2026-04-26

Author: Jessica Lyons

...
...

Two VMware vCenter vulnerabilities — CVE-2024-38812 (critical heap-overflow RCE) and CVE-2024-38813 (high-severity privilege escalation) — received initial patches that were later revised after Broadcom acknowledged the fixes did not fully address the issues; Broadcom has since confirmed exploitation in the wild, putting vCenter Server and VMware Cloud Foundation instances at risk of remote code execution and root escalation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.