VDB
CVE-2024-37086
CVE-2024-37086
PUBLISHED
Es besteht eine Schwachstelle in VMware ESXi und VMware Cloud Foundation. Dieser Fehler besteht aufgrund eines Out-of-bounds-Read. Ein lokaler Angreifer kann diese Schwachstelle ausnutzen, um einen Denial-of-Service-Zustand des Hosts zu erzeugen.
EPSS 0.08% · 23.7th percentile
Risk Scores
EPSS Score
0.08%
23.7th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Dell | Dell Storage PowerStore | |
| VMware | VMware Cloud Foundation | |
| VMware | VMware ESXi <ESXi70U3sq-23794019 | |
| VMware | VMware ESXi <ESXi80U3-24022510 |
Timeline
- Jun 25, 2024 CVE Published
- Jun 26, 2024 EPSS Score
- Jun 28, 2024 PoC Published
- Jul 18, 2024 EPSS Score
- Jul 30, 2024 PoC Published
- Jul 30, 2024 PoC Published
- Aug 1, 2024 PoC Published
- Aug 10, 2024 EPSS Score
- Sep 1, 2024 EPSS Score
- Sep 24, 2024 EPSS Score
- Oct 4, 2024 Coalition ESS Score
- Oct 16, 2024 EPSS Score
References
- https://wid.cert-bund.de/.well-known/csaf/white/2024/wid-sec-w-2024-1460.json advisory
- https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2024-1460 advisory
- https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24505 advisory
- https://www.microsoft.com/en-us/security/blog/2024/07/29/ransomware-operators-exploit-esxi-hypervisor-vulnerability-for-mass-encryption/ exploit
- https://www.dell.com/support/kbdoc/de-de/000228074/dsa-2024-365-dell-powerstore-family-security-update-for-vmware-vulnerabilities advisory