CISA KEV · catalog date Jan 23, 2026 · first observed Jul 19, 2026
Evidence dossier
CVE-2024-37079
vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol.
Exploited in the wild (CISA KEV since Jan 23, 2026). NVD reports CVSS 3.1 9.8. EPSS estimates 22.4% exploit likelihood as of Aug 27, 2026.
As of Aug 27, 2026
Normalized restatement
vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger this vulnerability by sending a specially crafted network packet potentially leading to remote code execution.
- State
- PUBLISHED
- Published
- Jun 18, 2024
- Updated
- Jan 24, 2026
- Evidence coverage
- 99%
Evidence chronology
What was known when
- Source dateSource date omittedFirst observed by CASCACISA-ADPOriginal evidence ↗
Record text: CISA ADP Vulnrichment
Inspect raw assertion
- Field
container- Value
- CISA ADP Vulnrichment
- Source dateSource date omittedFirst observed by CASCACVE ProgramOriginal evidence ↗
Record text: CVE Program Container
Inspect raw assertion
- Field
container- Value
- CVE Program Container
- Source dateSource date omittedFirst observed by CASCAvmwareOriginal evidence ↗
Record text: vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger this vulnerability by sending a specially crafted network packet potentially leading to remote code execution.
Inspect raw assertion
- Field
container- Value
- vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger this vulnerability by sending a specially crafted network packet potentially leading to remote code execution.
- Source dateFirst observed by CASCACISA KEVOriginal evidence ↗
Exploitation cataloged: Broadcom VMware vCenter Server Out-of-bounds Write Vulnerability
Inspect raw assertion
- Field
observed_exploitation- Value
- Broadcom VMware vCenter Server Out-of-bounds Write Vulnerability
- Source dateFirst observed by CASCAFIRST EPSSOriginal evidence ↗
EPSS score: 22.38% probability · 97.51th percentile
Inspect raw assertion
- Field
model_probability- Value
- Probability 0.223770000000; percentile 0.975130000000
FIRST EPSS · score date Aug 27, 2026 · 97.5th percentile · first observed Aug 27, 2026
NVD · CVSS 3.1 · first observed Jul 19, 2026 · same-version scores align in this snapshot
Evidence detail
Source limits and decisions
Why each evidence state has this value
Outside this view’s verified evidenceReason detail begins outside this selected snapshot; the state remains source-bound.
Source comparison
Who said what
CISA ADP Vulnrichment
Inspect raw assertion
- Field
container- Value
- CISA ADP Vulnrichment
CVE Program Container
Inspect raw assertion
- Field
container- Value
- CVE Program Container
vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger this vulnerability by sending a specially crafted network packet potentially leading to remote code execution.
Inspect raw assertion
- Field
container- Value
- vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger this vulnerability by sending a specially crafted network packet potentially leading to remote code execution.
Broadcom VMware vCenter Server Out-of-bounds Write Vulnerability
Inspect raw assertion
- Field
observed_exploitation- Value
- Broadcom VMware vCenter Server Out-of-bounds Write Vulnerability
22.38% probability · 97.51th percentile
Inspect raw assertion
- Field
model_probability- Value
- Probability 0.223770000000; percentile 0.975130000000
Applicability
Cited product scope
Grouped from 3 configuration nodes in this exact snapshot. Visual grouping is navigational; asset exposure and root cause require cited evidence.
Identity source boundaries
- Cpe dictionary1,775,266 records · observed through 2026-07-21T06:45:29.809Z
27d65b0f-b718-4b4f-bb79-c47c68d09dfa - Cpe match643,502 records · observed through 2026-07-21T08:13:17.697Z
955dae73-7302-438b-aee1-058d7cc5d48e
4 scope groups
Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "5.x"}, {"status": "affected", "version": "4.x"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "8.0", "lessThan": "8.0 U2d", "versionType": "custom"}, {"status": "affected", "version": "8.0", "lessThan": "8.0 U1e", "versionType": "custom"}, {"status": "affected", "version": "7.0", "lessThan": "7.0 U3r", "versionType": "custom"}]product-29d7e06677052d6292d0854ba656869395ea8e26a3dfe12b466a234813f9d5c3Linked exactInspect raw assertion
cpe:2.3:a:vmware:cloud_foundation:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 0
- Logic
- OR
- Version bounds
- from including 4.0; through excluding 5.2
- Match ID
7fa8dfe6-9c74-4711-a8af-3b170876a1f9
product-7b67c9fc3345279c14c2ffdcfdb4cfa4924c4b40fd0abb29ff5aeb5ac44092a7Linked exactInspect raw assertions
cpe:2.3:a:vmware:vcenter_server:7.0:update1:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 2 · node/0 · match 5
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
6d731c1a-9fe5-461c-97e2-6f45e4cbabe1
cpe:2.3:a:vmware:vcenter_server:7.0:update3p:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 2 · node/0 · match 29
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
a814f0ab-4aeb-4139-976f-425a4a9ec67b
cpe:2.3:a:vmware:vcenter_server:8.0:update2c:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 12
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
8ec8bef1-7908-46c0-841a-834778d1a863
cpe:2.3:a:vmware:vcenter_server:7.0:update3:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 2 · node/0 · match 14
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
6508a908-ef14-4a72-ac75-5da6f8b98a0e
cpe:2.3:a:vmware:vcenter_server:8.0:update1a:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 5
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
a5522514-8ed9-45db-9036-33fe40d77e7d
cpe:2.3:a:vmware:vcenter_server:7.0:update3l:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 2 · node/0 · match 25
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
3a422d04-48df-4a16-94f8-d5702cc2782d
cpe:2.3:a:vmware:vcenter_server:7.0:update1c:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 2 · node/0 · match 7
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
0fc6765a-6584-45a8-9b21-4951d2ea8939
cpe:2.3:a:vmware:vcenter_server:7.0:update3j:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 2 · node/0 · match 23
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
4f73aa9e-51e9-4fa0-813d-ad05fdc3ef94
cpe:2.3:a:vmware:vcenter_server:7.0:update3a:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 2 · node/0 · match 15
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
3bad2012-5c82-4ea9-a780-9bf1da5a18ab
cpe:2.3:a:vmware:vcenter_server:8.0:update1:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 4
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
c745a7e6-4760-48cd-b7c4-1c2c20217f21
cpe:2.3:a:vmware:vcenter_server:7.0:update3f:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 2 · node/0 · match 19
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
ad148a75-5076-416d-afd6-0f281da0a82b
cpe:2.3:a:vmware:vcenter_server:8.0:update1b:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 6
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
8c27c660-e917-4944-8b4c-41d9622b76d7
cpe:2.3:a:vmware:vcenter_server:8.0:update2b:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 11
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
98c1b77e-ab0e-4e8a-8294-2d3d230cdf9b
cpe:2.3:a:vmware:vcenter_server:7.0:update3d:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 2 · node/0 · match 17
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
adf46c54-313b-4742-a074-eea0a6554680
cpe:2.3:a:vmware:vcenter_server:7.0:update3o:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 2 · node/0 · match 28
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
8d8f6cc7-6b6d-4079-9e2c-a85c4616ff92
cpe:2.3:a:vmware:vcenter_server:7.0:update2:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 2 · node/0 · match 9
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
f4ca36c1-732e-41ae-b847-f7411b753f3d
cpe:2.3:a:vmware:vcenter_server:8.0:b:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 2
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
34d1f3b3-8e3f-4e4d-8ee6-2f593663b5cc
cpe:2.3:a:vmware:vcenter_server:7.0:update3k:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 2 · node/0 · match 24
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
455dd46e-a071-476d-8914-767485e45f35
cpe:2.3:a:vmware:vcenter_server:8.0:update2:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 9
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
604f559f-1775-4f29-996e-9079b99345b6
cpe:2.3:a:vmware:vcenter_server:7.0:update3n:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 2 · node/0 · match 27
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
34d8b182-4e71-4655-8dd8-743a3ef6dc8b
cpe:2.3:a:vmware:vcenter_server:7.0:update3g:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 2 · node/0 · match 20
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
956cea8c-f8c4-41bd-85b4-44fe3a772e50
cpe:2.3:a:vmware:vcenter_server:8.0:c:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 3
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
16f3d992-9f48-4604-9aaf-dc2d1ce98be2
cpe:2.3:a:vmware:vcenter_server:8.0:update2a:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 10
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
61dc9400-5aee-49ac-9925-0a96e32bd8c0
cpe:2.3:a:vmware:vcenter_server:7.0:update3h:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 2 · node/0 · match 21
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
008aea0f-116b-4af8-b3a7-3041cce25235
cpe:2.3:a:vmware:vcenter_server:7.0:update1a:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 2 · node/0 · match 6
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
8725e544-2a94-4829-a683-1ecce57a74a6
cpe:2.3:a:vmware:vcenter_server:7.0:update2c:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 2 · node/0 · match 12
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
188e103e-9568-4ce0-a984-141b2a9e82d2
cpe:2.3:a:vmware:vcenter_server:7.0:c:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 2 · node/0 · match 3
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
dca03b2a-48b2-48ad-b8eb-9d7bb2016819
cpe:2.3:a:vmware:vcenter_server:8.0:-:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
cc974ca1-88d3-42e4-bf1f-28870f8171b5
cpe:2.3:a:vmware:vcenter_server:8.0:update1d:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 8
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
67024a43-9e13-4f4e-b711-731792da3840
cpe:2.3:a:vmware:vcenter_server:7.0:update2d:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 2 · node/0 · match 13
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
b266439f-e911-4c95-9d27-88df96ddccd5
cpe:2.3:a:vmware:vcenter_server:7.0:update3e:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 2 · node/0 · match 18
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
9587f800-57bc-44b6-870e-95691684fc46
cpe:2.3:a:vmware:vcenter_server:7.0:update2a:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 2 · node/0 · match 10
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
0da882b6-d811-4e4b-b614-2d48f0b9036e
cpe:2.3:a:vmware:vcenter_server:7.0:update3m:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 2 · node/0 · match 26
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
806e9219-cdf4-4e62-978e-334e96a94ba6
cpe:2.3:a:vmware:vcenter_server:7.0:update2b:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 2 · node/0 · match 11
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
8d30a78e-16d0-4a2e-a2f8-f6073698243e
cpe:2.3:a:vmware:vcenter_server:8.0:update1c:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 7
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
56cfb469-b3e6-4503-a47c-d18206d4d19a
cpe:2.3:a:vmware:vcenter_server:7.0:update3c:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 2 · node/0 · match 16
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
58597f18-0b23-4d21-9aba-d9773958f10e
cpe:2.3:a:vmware:vcenter_server:7.0:-:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 2 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
5fa81ccd-a05e-498c-820e-21980e92132f
cpe:2.3:a:vmware:vcenter_server:7.0:a:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 2 · node/0 · match 1
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
0ee83406-a3d9-4f75-a1a6-63831cebeec1
cpe:2.3:a:vmware:vcenter_server:7.0:update1d:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 2 · node/0 · match 8
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
85dd238c-ef73-44f0-928e-a94ff5c4b378
cpe:2.3:a:vmware:vcenter_server:7.0:update3i:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 2 · node/0 · match 22
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
ee486b2f-aed4-4fce-a674-dfc25844feff
cpe:2.3:a:vmware:vcenter_server:7.0:b:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 2 · node/0 · match 2
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
fb563627-c9cf-4d8a-b882-9ab65eae9e15
cpe:2.3:a:vmware:vcenter_server:7.0:d:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 2 · node/0 · match 4
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
a2392d0f-d7a2-4e01-9212-1ba6c895aebf
cpe:2.3:a:vmware:vcenter_server:8.0:a:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 1
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
efe63984-f69b-4593-9aec-d179d6d98b08
Affected-product evidence
Accepted scope and product mapping
0 canonical links · 0 source-reported links
Applicability remains source-scoped; safety and exposure remain unassessed.
Assessments
CVSS by origin
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HEvidence boundaries
- KEV membership is authoritative for the catalog, not proof of exposure in any environment.
- EPSS is a dated model probability and not an individual-environment prediction.
- Affected or fixed status applies only to the exact cited product and version scope; remaining scope stays source-scoped.
- NVD-carried upstream facts remain derivative; independent corroboration requires a separately authored source.
- Only NVD metrics validated under the generation-bound calculator are Public Priority eligible; direct CVE record metrics remain display-only.
- NVD CVSS source eligibility is closed: NVD-authored, exact record-source, or registered same-CVE container origin; unmapped sources remain display-only.
- Affected-product evidence remains source-scoped; canonical linkage is required before applicability scoring.
- Core replay supports the active and immediately prior generation; retrospective valid-at replay is deferred.
- OSV aggregation and OSV-converted NVD material are not independent corroboration.
- Red Hat facts are vendor assertions for the exact supplied products.
- Nonmembership and not-yet-observed states are not proof of safety.