logo

CVE-2024-37079: VMware vCenter Server Integer Underflow Code Execution Vulnerability

ID: f855406a-6a8f-5bd5-9130-1b2fea4ca98b

STIX ID: report--f855406a-6a8f-5bd5-9130-1b2fea4ca98b

Feed Name: Zero Day Initiative (ZDI) Blog

Threat Score
70/100

Date Published: 2024-08-28

Date Updated: 2026-05-01

Author: Trend Micro Research Team

...
...

This report analyzes a critical DCE/RPC vulnerability where an integer underflow in authentication trailer processing (triggered by Bind/Alter Context packets with 169 presentation contexts and a non-zero auth_len) can produce a heap buffer overflow—demonstrated using SPNEGO SRP—and potentially allow remote unauthenticated arbitrary code execution; the vendor issued a patch in June and no active exploitation has been observed, with detection guidance recommending monitoring DCE/RPC on ports 2012/2014/2020 and flagging Bind/Alter Context messages where auth_len>0 and n_context_elem>=169.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.