EUVD-2024-36412
vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger this vulnerability by sending a specially crafted network packet potentially leading to remote code execution.
- EUVD state
- Present in the current official mapping
- Known exploitation
- Recorded by ENISA since 23 Jan 2026. Evidence sources: cisa_kev.
- ENISA score
- 9.8 · CVSS 3.1
- Advisory evidence
- 2 linked advisory records
Only statements that explicitly mention a fix, patch, update, workaround or mitigation are shown here.
- csaf_ncscnl · NCSC-2024-0262Kwetsbaarheden verholpen in VMware vCenter
