VDB

CVE-2024-38813

CVE-2024-38813 PUBLISHED KEV

------------ On September 17, 2024 Broadcom released a critical VMware Security Advisory (VMSA), VMSA-2024-0019, addressing security vulnerabilities found and resolved in VMware vCenter. The advisory was updated on October 21, 2024 with updated software packages to address security and functional issues reported after the original disclosure. The updated advisory contains patches applicable to vCenter 7.0.3, 8.0.2, and 8.0.3. All customers should apply these refreshed updates. The VMSA will always be the source of truth for what products & versions are affected and proper patches to keep your organization secure. This document is a corollary to the advisory and includes self-service information to help you and your organization decide how to respond. These vulnerabilities are memory management and corruption issues which can be used against VMware vCenter services, potentially allowing remote code execution. You are affected if you are running any version of vSphere or VMware Cloud Foundation prior to the versions listed in the VMSA. Please consult the VMSA itself for the definitive list of affected versions. If you have a question about whether you are affected it is likely that you are, and should take action immediately.

EPSS 29.53% · 96.7th percentile

Risk Scores

EPSS Score
29.53%
96.7th percentile

Timeline

  • Sep 17, 2024 CVE Published
  • Sep 17, 2024 PoC Published
  • Sep 18, 2024 EPSS Score
  • Sep 18, 2024 PoC Published
  • Sep 18, 2024 PoC Published
  • Sep 18, 2024 PoC Published
  • Sep 19, 2024 PoC Published
  • Sep 19, 2024 PoC Published
  • Sep 19, 2024 PoC Published
  • Sep 23, 2024 PoC Published
  • Oct 4, 2024 Coalition ESS Score
  • Oct 22, 2024 PoC Published
Open in Interactive Console →
$ Console Community · 100/wk Open console ›