logo

Critical VMware vCenter Server Patch

ID: 3550a62c-5a71-524e-a1b8-b888789ef6af

STIX ID: report--3550a62c-5a71-524e-a1b8-b888789ef6af

Feed Name: Kudelski Security

Threat Score
75/100

Date Published: 2024-09-18

Date Updated: 2026-07-22

...
...

VMware released advisory VMSA-2024-0019 for two critical vCenter Server vulnerabilities: CVE-2024-38812 (heap overflow in DCERPC enabling remote code execution, CVSS 9.8) and CVE-2024-38813 (network-based privilege escalation to root, CVSS 7.5). Affected products include vCenter, VMware vSphere and VMware Cloud Foundation; administrators are advised to take a non-memory snapshot of the VCSA and apply the vendor updates promptly. The report also states that Kudelski Security/CFC has not observed active exploitation to date.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.