tag
VCenter
CVE-2024-37079
network
CRITICAL 9.8
KEV
EPSS 22%
VMware vCenter Server DCE/RPC Heap Overflow RCE (CVE-2024-37079)
CVE-2024-37079 is a critical heap overflow condition in a vCenter Server DCE/RPC network-handling path. A crafted network packet can trigger memory corruption pre-authentication and potentially lead to remote code execution. Public reporting indicates patch…
Patched
2026-05-16
CVE-2024-37085
network
MEDIUM 6.8
KEV
Ransomware
EPSS 26%
VMware ESXi Active Directory Authentication Bypass (CVE-2024-37085)
CVE-2024-37085 is an authentication bypass in domain-joined VMware ESXi environments where AD group membership manipulation can grant administrator-level ESXi access without valid local ESXi credentials. Public reporting links this issue to real-world…
Patched
2026-05-16