CISA Known Exploited Vulnerability (KEV)
VMware vCenter Server Heap-Based Buffer Overflow Vulnerability
November 20, 2024
December 11, 2024
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Description
The vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger this vulnerability by sending a specially crafted network packet potentially leading to remote code execution.