CVE-2024-38812Active Exploitation(vmware / cloud_foundation)

LOWCVSS 9.8 · CRITICALCISA KEV

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Prioritize remediation for vmware cloud_foundation systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

The vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger this vulnerability by sending a specially crafted network packet potentially leading to remote code execution.

3.5/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2024-12-11. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-122CWE-787

Priority

LOW

Exploitation

ACTIVE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • cloud_foundation
  • vcenter_server

Threat summary

  • Active exploitation appears in 2 classified signals
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 2 signals
  • Technical details provided in 3 signals
  • General: 1 classified signal
  • Peaked 2d ago at 2 mentions (2026-08-04); latest day: 1
  • 4 total mentions across 3 days

Affected systems

Vendors
Products
cloud_foundationvcenter_server

2 versions affected across 2 products

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-08-04: 2Mentions · 2026-09-05: 1Mentions · 2026-09-16: 1Active Exploitation · 2026-08-04: 1Active Exploitation · 2026-09-05: 1Technical Details · 2026-08-04: 2Technical Details · 2026-09-05: 108-0409-0509-16
Signal classification2 categories
Active Exploitation
266.7%
General
133.3%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-08-042
Active Exploitation1General1
2026-09-051
Active Exploitation1
Full discourse4 posts
  • Aviatrix Threat Research Center@aviatrixtrc
    Active Exploitation

    TRC analysis shows attackers exploiting CVE-2024-38812 and CVE-2024-38813 to achieve VM-to-host escape in VMware Workstation/Fusion environments. Once hypervisor access is gained, lateral movement to other VMs becomes trivial. Runtime segmentation helps contain post-compromise activity across virtualized infrastructure. #CloudSecurity 🔗 Full TRC analysis: https://aviatrix.ai/threat-research-center/critical-vmware-workstation-fusion-flaw-cve-2026-59346

    Post summary

    Attackers are actively exploiting CVE‑2024‑38812 and CVE‑2024‑38813 to escape from VMware Workstation/Fusion VMs to the host, enabling easy lateral movement across virtual infrastructure.

    0001073
    2.0K followersView on X
  • Tao Idr@tao_officiel
    Active Exploitation

    5/ It’s not theoretical: 2024’s VMware vCenter Server heap overflow (CVE-2024-38812) scored a 9.8 CVSS and was actively exploited. Defense: Canaries & ASLR raise the bar, but are only mitigations. Real fixes require bounds-checked input handling & memory-safe languages.

    Post summary

    The post highlights that VMware vCenter Server CVE-2024-38812, a 9.8‑scored heap overflow, is actively exploited, with mitigations like canaries and ASLR noted but a formal patch unavailable.

    1000059
    150 followersView on X
  • Aviatrix Threat Research Center@aviatrixtrc

    Ransomware gangs are actively exploiting CVE-2024-38812 for unauthenticated RCE on VMware vCenter servers. TRC analysis shows attackers pivot from compromised vCenter to laterally traverse virtualized infrastructure before deploying encryption payloads. Runtime segmentation limits blast radius across virtual environments. #CloudSecurity 🔗 Full TRC analysis: https://aviatrix.ai/threat-research-center/cisa-critical-vmware-vcenter-rce-cve-2026-59310-ransomware-gangs

    0000063
    2.0K followersView on X
  • Tao Idr@tao_officiel
    General

    6/ This methodology is part of the buffer overflow & firewall evasion testing Tao IDR runs during pentests. 📚 Sources: MITRE CWE Top 25, NSA/CISA, CVE-2024-38812, FBI/CISA. #BufferOverflow #PenetrationTesting #EthicalHacking #CyberSecurity #TaoIDR

    Post summary

    Tao IDR references CVE‑2024‑38812 in its buffer overflow and firewall evasion testing methodology, but does not provide specific exploit details, patches, or evidence of active use.

    0000035
    150 followersView on X
CPE platform detail49 entries

49 of 49 entries

PartVendorProductVersionTarget SWTarget HW
Appvmwarecloud_foundation---
Appvmwarevcenter_server7.0--
Appvmwarevcenter_server7.0--
Appvmwarevcenter_server7.0--
Appvmwarevcenter_server7.0--
Appvmwarevcenter_server7.0--
Appvmwarevcenter_server7.0--
Appvmwarevcenter_server7.0--
Appvmwarevcenter_server7.0--
Appvmwarevcenter_server7.0--
Appvmwarevcenter_server7.0--
Appvmwarevcenter_server7.0--
Appvmwarevcenter_server7.0--
Appvmwarevcenter_server7.0--
Appvmwarevcenter_server7.0--
Appvmwarevcenter_server7.0--
Appvmwarevcenter_server7.0--
Appvmwarevcenter_server7.0--
Appvmwarevcenter_server7.0--
Appvmwarevcenter_server7.0--
Appvmwarevcenter_server7.0--
Appvmwarevcenter_server7.0--
Appvmwarevcenter_server7.0--
Appvmwarevcenter_server7.0--
Appvmwarevcenter_server7.0--
Appvmwarevcenter_server7.0--
Appvmwarevcenter_server7.0--
Appvmwarevcenter_server7.0--
Appvmwarevcenter_server7.0--
Appvmwarevcenter_server7.0--
Appvmwarevcenter_server7.0--
Appvmwarevcenter_server7.0--
Appvmwarevcenter_server7.0--
Appvmwarevcenter_server7.0--
Appvmwarevcenter_server8.0--
Appvmwarevcenter_server8.0--
Appvmwarevcenter_server8.0--
Appvmwarevcenter_server8.0--
Appvmwarevcenter_server8.0--
Appvmwarevcenter_server8.0--
Appvmwarevcenter_server8.0--
Appvmwarevcenter_server8.0--
Appvmwarevcenter_server8.0--
Appvmwarevcenter_server8.0--
Appvmwarevcenter_server8.0--
Appvmwarevcenter_server8.0--
Appvmwarevcenter_server8.0--
Appvmwarevcenter_server8.0--
Appvmwarevcenter_server8.0--

Explore more