Vulnerability record · CVE-2015-2342 · published 12 October 2015
CVE-2015-2342: VMware vCenter JMX RMI MBean registration allows remote code execution
Vmware · Vcenter Server
The JMX RMI service in VMware vCenter Server does not restrict registration of MBeans, letting a remote attacker register a malicious MBean and execute arbitrary code over the RMI protocol. Because vCenter is a central management component, compromise can expose the virtual infrastructure it controls. The record does not state whether authentication is required beyond the network vector.
Description
The JMX RMI service in VMware vCenter Server 5.0 before u3e, 5.1 before u3b, 5.5 before u3, and 6.0 before u1 does not restrict registration of MBeans, which allows remote attackers to execute arbitrary code via the RMI protocol.
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
critical priorityThe flaw allows unauthenticated remote code execution on a central management server, and the very high EPSS score signals strong likelihood of exploitation.
What it is
The JMX RMI service in VMware vCenter Server does not restrict registration of MBeans, letting a remote attacker register a malicious MBean and execute arbitrary code over the RMI protocol. Because vCenter is a central management component, compromise can expose the virtual infrastructure it controls. The record does not state whether authentication is required beyond the network vector.
Impact
An unauthenticated network attacker can execute arbitrary code with the privileges of the vCenter JMX service, potentially taking control of the management server and the virtual environment it administers.
Attack surface
Reachable over the network via the RMI protocol on the JMX service; the CVSS vector AV:N/AC:L/Au:N indicates no authentication and no user interaction are needed. The description does not specify the exact port or whether the service is exposed by default.
Exploitation
Not listed in CISA KEV and no ransomware associations are recorded, but EPSS is very high (0.89048, 99.77th percentile), indicating substantial predicted exploitation activity. Reference tags include only Patch and Vendor Advisory, with no public exploit tag.
What to do
- Apply the VMware vCenter Server updates referenced in VMSA-2015-0007 (5.0 u3e, 5.1 u3b, 5.5 u3, 6.0 u1 or later).
- Restrict network access to the JMX RMI service so only trusted management hosts can reach it.
- Disable or firewall the JMX RMI interface if it is not required for operations.
- Monitor vCenter and its host for unexpected MBean registrations or process execution.
- Review vCenter for signs of compromise and rotate credentials for accounts with management access.
Detection
- Monitor network traffic to the vCenter JMX RMI port for unexpected external connections.
- Audit vCenter logs for MBean registration events or JMX service errors.
- Alert on new or unusual child processes spawned by the vCenter JMX service.
- Track authentication and configuration changes on vCenter hosts for anomalies.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2015-2342 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2015-2342), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.