CISA Warns of Critical VMware vCenter RCE Vulnerability Now Exploited in Attacks
The Cybersecurity and Infrastructure Security Agency (CISA) has added a critical vulnerability concerning VMware's vCenter Server to its Known Exploited Vulnerabilities (KEV) catalog. This vulnerability, identified as CVE-2024-37079 , poses a significant…
The Cybersecurity and Infrastructure Security Agency (CISA) has added a critical vulnerability concerning VMware's vCenter Server to its Known Exploited Vulnerabilities (KEV) catalog. This vulnerability, identified as CVE-2024-37079 , poses a significant risk due to confirmed active exploitation.
The vulnerability is categorized as an out-of-bounds write issue linked to the DCERPC (Distributed Computing Environment / Remote Procedure Calls) protocol. Exploitation allows unauthorized network access to execute remote code on the vCenter Server, potentially compromising the entire system.
This flaw arises from improper memory management within the DCERPC protocol implementation. An attacker can exploit it by dispatching specifically crafted network packets to the vCenter Server. Given vCenter's role as a central management tool for VMware vSphere environments, a breach could enable lateral movement across virtualized infrastructures.
The vulnerability is associated with CWE-787 ( Out-of-bounds Write ) and is particularly concerning as it requires no user interaction and is network-based.
This vulnerability, identified as CVE-2024-37079 , poses a significant risk due to confirmed active exploitation.
CISA has mandated that Federal Civilian Executive Branch (FCEB) agencies address this vulnerability by February 13, 2026, following its inclusion in the KEV catalog on January 23, 2026. Organizations are urged to prioritize patching, applying vendor-provided mitigations, or discontinuing use if necessary.
Broadcom has released updates to mitigate this issue. Administrators are advised to upgrade to the latest secure versions.
To protect against this threat, recommended actions include:
Patch Immediately: Apply patches as outlined in Broadcom's security advisory. Network Segmentation: Restrict vCenter Server interfaces from public internet exposure and limit access to trusted networks. Monitor Traffic: Implement monitoring for unusual DCERPC traffic targeting vCenter servers. Review Logs: Audit access logs for unauthorized connection attempts to the management interface.
Organizations have a limited timeframe to address this critical vulnerability before it becomes a common target for automated exploitation tools.
Based on reporting by Cyber Security News.
