logo

Critical VMware Bugs Open Swaths of VMs to RCE, Data Theft

ID: d4956896-7a1e-5d70-9c37-b601ad08e01d

STIX ID: report--d4956896-7a1e-5d70-9c37-b601ad08e01d

Feed Name: Dark Reading

Threat Score
70/100

Date Published: 2024-06-18

Date Updated: 2026-04-21

Author: Nate Nelson, Contributing Writer

...
...

Broadcom/VMware released patches for three vCenter vulnerabilities: two critical DCERPC heap-overflow flaws (CVE-2024-37079, CVE-2024-37080) enabling remote code execution (CVSS 9.8) and a high-severity local privilege escalation via sudo misconfiguration (CVE-2024-37081, CVSS 7.8). The advisory stresses immediate patching given vCenter’s central role in managing large VM estates and the broad potential impact, though there is currently no evidence these bugs have been exploited in the wild.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.