VMware vCenter Server updates address heap-overflow and privilege escalation vulnerabilities (CVE-2024-38812, CVE-2024-38813)
search cancel

VMware vCenter Server updates address heap-overflow and privilege escalation vulnerabilities (CVE-2024-38812, CVE-2024-38813)

book

Article ID: 381185

calendar_today

Updated On:

Products

VMware vCenter Server 6.0

Issue/Introduction

VMware vCenter Server has been identified with a heap-overflow vulnerability in the implementation of the DCERPC protocol . This affects only vCenter 7.x version and above. vCenter versions running on 6.5 and 6.7 are not affected by this vulnerability. In vCenter version 7.0 and higher vimdird process binds with ports (2012 & 636) during binding it downgrades the privilege from root to vimdird privilege, whereas in Vcenter 6.5 & 6.7 versions the vimdird process always runs only with root privilege

Environment

vCenter 7.x and 8.x

Cause

  • In vCenter Server version 7.0 and higher, the vmdird process binds with ports 2012 & 636.
  • A malicious actor with network access to vCenter Server may trigger this vulnerability by sending a specially crafted network packet potentially leading to remote code execution.

Resolution

Additional Information

For more details about VMSA-2024-0019