VMware fixes bad patch for critical vCenter Server RCE flaw
ID: a950a046-de46-5db3-ac2b-eb1c6971c94f
STIX ID: report--a950a046-de46-5db3-ac2b-eb1c6971c94f
Feed Name: Bleeping Computer
Threat Score
VMware released updated security patches to fully address CVE-2024-38812, a critical (CVSS 9.8) vCenter Server heap overflow in the DCE/RPC implementation that enables unauthenticated remote code execution; earlier September patches did not fully fix the issue so Broadcom/VMware issued new updates for supported 7.0 and 8.0 builds, while older end-of-support versions remain vulnerable and no workarounds exist.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
