CVE-2024-37080
------------ On June 17, 2024 VMware released a critical security advisory, VMSA-2024-0012, addressing security vulnerabilities found and resolved in VMware vCenter Server, which is present in VMware vSphere and VMware Cloud Foundation products. The VMSA will always be the source of truth for what products & versions are affected, the workarounds, and proper patches to keep your organization secure. This document is a corollary to the advisory and includes self-service information to help you and your organization decide how to respond. These vulnerabilities are memory management and corruption issues which can be used against VMware vCenter Server services, potentially allowing remote code execution.
EPSS 24.91% · 96.3th percentile
Risk Scores
Timeline
- Jun 17, 2023 CVE Published
- Jun 18, 2024 EPSS Score
- Jun 19, 2024 PoC Published
- Aug 28, 2024 PoC Published
- Oct 4, 2024 Coalition ESS Score
- Mar 13, 2025 Coalition ESS Score
- Mar 14, 2025 Coalition ESS Score
- Mar 14, 2025 PoC Published
- Mar 21, 2025 EPSS Score
- Mar 25, 2025 EPSS Score
- Mar 26, 2025 EPSS Score
- Mar 30, 2025 EPSS Score