Target Industry

Indiscriminate, opportunistic targeting.

Overview

VMware has disclosed details relating to these vulnerabilities for VMware vCenter Server and products that contain vCenter Server (vSphere and Cloud Foundation):

CVE-2024-37079 (CVSSv3 score: 9.8): vCenter Server heap-overflow vulnerability of the DCERPC protocol

CVE-2024-37080 (CVSSv3: 9.8): vCenter Server heap-overflow vulnerability of the DCERPC protocol

CVE-2024-37081 (CVSSv3: 7.8): vCenter Server multiple local privilege escalation vulnerabilities due to misconfiguration of sudo.

Impact

Successful exploitation of CVE-2024-37079 or CVE-2024-37080 allows threat actors with network access to vCenter Server to potentially run remote code executions on the target machine.

Exploitation of CVE-2024-37081 allows an authenticated local user with non-administrative privileges to exploit vulnerabilities to elevate privileges to root on VCenter Server appliance.

Vulnerability Detection

VMware have released patched versions of vCenter Server and Cloud Foundation. Older versions of vSphere, versions 6.5 and 6.7, will not be patched as they are past their End of General Support dates.

Affected Products

Devices running VMware vCenter Server and products that contain vCenter Server (vSphere and Cloud Foundation).

Containment, Mitigations & Remediations

It is highly recommended that all organisations run the relevant patches as soon as possible.

More information can be found on VMware Update Guide.

Indicators of Compromise

No indicators of compromise (IoCs) are available currently.

Threat Landscape

VMware vCenter Server is used on many devices as it is the centralised management utility for VMware, which is one of the main types of software used for virtual machines. Multiple notable exploits have been disclosed by VMware in relation to VMware vCenter Server and any products that contain vCenter Server. As many devices have not run the latest patch, this leaves them open to possible exploitation by threat actors.

Threat Group

No attribution to specific threat actors or groups has been identified at the time of writing.

Mitre Methodologies

Tactic:

TA0002 – Execution

TA0004 – Privilege Escalation

Further Information

VMware Update Guide.

 

Further Threat Intelligence from Quorum Cyber

Headquarters

Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ

FLORIDA, USA Office

501 E Kennedy Blvd.
STE 1400
Tampa FL 33602

Ontario, Canada Office

1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7

Contact Us
Address

Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ

501 E Kennedy Blvd
STE 1400
Tampa FL 33602

1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7

HEADQUARTERS
Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ



FLORIDA, USA OFFICE
501 E Kennedy Blvd.
STE 1400
Tampa FL 33602


ONTARIO, CANADA OFFICE
1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7


Legal

Privacy Preference Center

Skip to content