Skip to main content

VMware vCenter Server vulnerabilities

1 published alerts for Broadcom VMware vCenter Server.

Actively exploited (KEV)

CVE-2024-37079

Broadcom VMware vCenter Server Out-of-bounds Write Vulnerability

Broadcom VMware vCenter Server is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2024-37079). Broadcom VMware vCenter Server contains an out-of-bounds write vulnerability in the implementation of the DCERPC protocol. This could allow a malicious actor with network access to vCenter Server to send specially crafted network packets, potentially leading to remote code execution. CISA remediation due date: 2026-02-13. If you need help checking exposure, call (864) 335-9223.