Target Industry
Indiscriminate, opportunistic targeting.
Overview
VMware has disclosed details relating to these vulnerabilities for VMware vCenter Server and products that contain vCenter Server (vSphere and Cloud Foundation):
CVE-2024-37079 (CVSSv3 score: 9.8): vCenter Server heap-overflow vulnerability of the DCERPC protocol
CVE-2024-37080 (CVSSv3: 9.8): vCenter Server heap-overflow vulnerability of the DCERPC protocol
CVE-2024-37081 (CVSSv3: 7.8): vCenter Server multiple local privilege escalation vulnerabilities due to misconfiguration of sudo.
Impact
Successful exploitation of CVE-2024-37079 or CVE-2024-37080 allows threat actors with network access to vCenter Server to potentially run remote code executions on the target machine.
Exploitation of CVE-2024-37081 allows an authenticated local user with non-administrative privileges to exploit vulnerabilities to elevate privileges to root on VCenter Server appliance.
Vulnerability Detection
VMware have released patched versions of vCenter Server and Cloud Foundation. Older versions of vSphere, versions 6.5 and 6.7, will not be patched as they are past their End of General Support dates.
Affected Products
Devices running VMware vCenter Server and products that contain vCenter Server (vSphere and Cloud Foundation).
Containment, Mitigations & Remediations
It is highly recommended that all organisations run the relevant patches as soon as possible.
More information can be found on VMware Update Guide.
Indicators of Compromise
No indicators of compromise (IoCs) are available currently.
Threat Landscape
VMware vCenter Server is used on many devices as it is the centralised management utility for VMware, which is one of the main types of software used for virtual machines. Multiple notable exploits have been disclosed by VMware in relation to VMware vCenter Server and any products that contain vCenter Server. As many devices have not run the latest patch, this leaves them open to possible exploitation by threat actors.
Threat Group
No attribution to specific threat actors or groups has been identified at the time of writing.
Mitre Methodologies
Tactic:
TA0002 – Execution
TA0004 – Privilege Escalation
Further Information













