CVE-2024-37079: VMware vCenter Server Integer Underflow Code Execution Vulnerability
ID: f855406a-6a8f-5bd5-9130-1b2fea4ca98b
STIX ID: report--f855406a-6a8f-5bd5-9130-1b2fea4ca98b
Feed Name: Zero Day Initiative (ZDI) Blog
This report analyzes a critical DCE/RPC vulnerability where an integer underflow in authentication trailer processing (triggered by Bind/Alter Context packets with 169 presentation contexts and a non-zero auth_len) can produce a heap buffer overflow—demonstrated using SPNEGO SRP—and potentially allow remote unauthenticated arbitrary code execution; the vendor issued a patch in June and no active exploitation has been observed, with detection guidance recommending monitoring DCE/RPC on ports 2012/2014/2020 and flagging Bind/Alter Context messages where auth_len>0 and n_context_elem>=169.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
