Critical Security Vulnerability in VMware vCenter Server Fixed
Security vulnerabilities allowing remote code execution and privilege escalation in VMware vCenter Server have been fixed.

VMware has announced patches for various security vulnerabilities that allow remote code execution or privilege escalation in the vCenter Server solution.
Two of these security vulnerabilities (CVE-2024-37079 and CVE-2024-37080) are considered critical and affect the implementation of the DCERPC protocol. VMware states that, "a malicious actor with network access to vCenter Server could exploit these vulnerabilities by sending specially crafted network packets and potentially cause remote code execution."
VMware warns customers about CVE-2024-37081, a vulnerability with high severity that could lead to privilege escalation due to a Sudo misconfiguration.
Source: Fixed Critical Vulnerability in VMware vCenter Server (itsecurity.pt)