CISA Adds Actively Exploited VMware vCenter Flaw CVE-2024-37079 to KEV Catalog
好的,我现在需要帮用户总结一篇文章,控制在100字以内。首先,我得仔细阅读文章内容,抓住关键点。 文章主要讲的是美国CISA将Broadcom VMware vCenter Server的一个严重漏洞加入已知被利用漏洞目录。这个漏洞CVE-2024-37079,CVSS评分9.8,属于堆溢出问题,可能导致远程代码执行。发现者是奇安信的研究人员,并且该漏洞已经在野被利用。 接下来,我需要将这些信息浓缩到100字以内。要包括CISA的行动、漏洞的严重性、影响范围以及发现者和修复情况。 可能会忽略一些细节,比如其他漏洞CVE-2024-37080和CVE-2024-38812、38813,以及具体的攻击链和后续修复时间。但为了简洁,这些可以省略。 最后,确保语言流畅自然,不使用任何格式化符号。 </think> 美国网络安全机构CISA将Broadcom VMware vCenter Server的严重漏洞CVE-2024-37079加入已知被利用漏洞目录,该漏洞可导致远程代码执行。中国奇安信研究人员发现并报告此漏洞及其他相关问题。 2026-1-24 08:9:0 Author: thehackernews.com(查看原文) 阅读量:0 收藏

Vulnerability / Enterprise Security

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added a critical security flaw affecting Broadcom VMware vCenter Server that was patched in June 2024 to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation in the wild.

The vulnerability in question is CVE-2024-37079 (CVSS score: 9.8), which refers to a heap overflow in the implementation of the DCE/RPC protocol that could allow a bad actor with network access to vCenter Server to achieve remote code execution by sending a specially crafted network packet.

It was resolved by Broadcom in June 2024, along with CVE-2024-37080, another heap overflow in the implementation of the DCE/RPC protocol that could lead to remote code execution. Chinese cybersecurity company QiAnXin LegendSec researchers Hao Zheng and Zibo Li were credited with discovering and reporting the issues.

Cybersecurity

In a presentation at the Black Hat Asia security conference in April 2025, the researchers said the two flaws are part of a set of four vulnerabilities – three heap overflows and one privilege escalation – that were discovered in the DCE/RPC service. The two other flaws, CVE-2024-38812 and CVE-2024-38813, were patched by Broadcom in September 2024.

In particular, they found that one of the heap overflow vulnerabilities could be chained with the privilege escalation vulnerability (CVE-2024-38813) to achieve unauthorized remote root access and ultimately gain control over ESXi.

It's currently not known how CVE-2024-37079 is being exploited, if it's the work of any known threat actor or group, or the scale of such attacks. However, Broadcom has since updated its advisory to officially confirm in-the-wild abuse of the vulnerability.

"Broadcom has information to suggest that exploitation of CVE-2024-37079 has occurred in the wild," the company said in its update.

In light of active exploitation, Federal Civilian Executive Branch (FCEB) agencies are required to update to the latest version by February 13, 2026, for optimal protection.

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.


文章来源: https://thehackernews.com/2026/01/cisa-adds-actively-exploited-vmware.html
如有侵权请联系:admin#unsafe.sh