logo

VMware fixes bad patch for critical vCenter Server RCE flaw

ID: a950a046-de46-5db3-ac2b-eb1c6971c94f

STIX ID: report--a950a046-de46-5db3-ac2b-eb1c6971c94f

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2024-10-22

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

VMware released updated security patches to fully address CVE-2024-38812, a critical (CVSS 9.8) vCenter Server heap overflow in the DCE/RPC implementation that enables unauthenticated remote code execution; earlier September patches did not fully fix the issue so Broadcom/VMware issued new updates for supported 7.0 and 8.0 builds, while older end-of-support versions remain vulnerable and no workarounds exist.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.