← Vulnerability feed

Vulnerability record · CVE-2015-2342 · published 12 October 2015

CVE-2015-2342: VMware vCenter JMX RMI MBean registration allows remote code execution

Vmware · Vcenter Server

The JMX RMI service in VMware vCenter Server does not restrict registration of MBeans, letting a remote attacker register a malicious MBean and execute arbitrary code over the RMI protocol. Because vCenter is a central management component, compromise can expose the virtual infrastructure it controls. The record does not state whether authentication is required beyond the network vector.

10.0 CVSS 2.0 High EPSS 89% · top 0.2%
10.0CVSS 2.0 base score
89%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
12References
17 Jun 2026Last modified by NVD

Description

The JMX RMI service in VMware vCenter Server 5.0 before u3e, 5.1 before u3b, 5.5 before u3, and 6.0 before u1 does not restrict registration of MBeans, which allows remote attackers to execute arbitrary code via the RMI protocol.

AV:N/AC:L/Au:N/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: medium.

critical priorityThe flaw allows unauthenticated remote code execution on a central management server, and the very high EPSS score signals strong likelihood of exploitation.

What it is

The JMX RMI service in VMware vCenter Server does not restrict registration of MBeans, letting a remote attacker register a malicious MBean and execute arbitrary code over the RMI protocol. Because vCenter is a central management component, compromise can expose the virtual infrastructure it controls. The record does not state whether authentication is required beyond the network vector.

Impact

An unauthenticated network attacker can execute arbitrary code with the privileges of the vCenter JMX service, potentially taking control of the management server and the virtual environment it administers.

Attack surface

Reachable over the network via the RMI protocol on the JMX service; the CVSS vector AV:N/AC:L/Au:N indicates no authentication and no user interaction are needed. The description does not specify the exact port or whether the service is exposed by default.

Exploitation

Not listed in CISA KEV and no ransomware associations are recorded, but EPSS is very high (0.89048, 99.77th percentile), indicating substantial predicted exploitation activity. Reference tags include only Patch and Vendor Advisory, with no public exploit tag.

What to do

  • Apply the VMware vCenter Server updates referenced in VMSA-2015-0007 (5.0 u3e, 5.1 u3b, 5.5 u3, 6.0 u1 or later).
  • Restrict network access to the JMX RMI service so only trusted management hosts can reach it.
  • Disable or firewall the JMX RMI interface if it is not required for operations.
  • Monitor vCenter and its host for unexpected MBean registrations or process execution.
  • Review vCenter for signs of compromise and rotate credentials for accounts with management access.

Detection

  • Monitor network traffic to the vCenter JMX RMI port for unexpected external connections.
  • Audit vCenter logs for MBean registration events or JMX service errors.
  • Alert on new or unusual child processes spawned by the vCenter JMX service.
  • Track authentication and configuration changes on vCenter hosts for anomalies.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2015-2342 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2026-59310VMware vCenter Syslog server path traversal leads to RCEVMware vCenter's Syslog server is affected by a directory traversal flaw (CWE-22) that allows a remote, unauthenticated attacker to execute arbitrary…KEVEPSS 2.6%analysed9.8CVE-2024-38813VMware vCenter Server privilege escalation to root via crafted packetvCenter Server contains a privilege escalation flaw where a malicious actor with network access can send a specially crafted network packet to escala…KEVEPSS 17%analysed9.8CVE-2024-38812VMware vCenter Server DCERPC heap overflow allows remote code executionvCenter Server contains a heap-based buffer overflow (CWE-122/CWE-787) in its DCERPC protocol implementation. A remote, unauthenticated attacker can …KEVEPSS 55%analysed9.8CVE-2024-37079VMware vCenter Server DCERPC heap overflow allows remote code executionvCenter Server contains a heap-overflow (out-of-bounds write) in its DCERPC protocol implementation. A remote, unauthenticated attacker can send a cr…KEVEPSS 22%analysed9.8CVE-2023-34048VMware vCenter Server DCERPC out-of-bounds writevCenter Server contains an out-of-bounds write in its DCERPC protocol implementation. A remote, unauthenticated attacker with network access can trig…KEVEPSS 99%analysed9.8CVE-2021-22005VMware vCenter Server Analytics arbitrary file upload to RCEThe Analytics service in VMware vCenter Server accepts a specially crafted file upload, which the product mishandles as a path traversal issue (CWE-2…KEVEPSS 100%analysed9.8CVE-2021-21985VMware vCenter Server Virtual SAN Health Check plug-in RCEThe vSphere Client (HTML5) in vCenter Server fails to validate input in the Virtual SAN Health Check plug-in, which is enabled by default. This allow…KEVEPSS 100%analysed9.8CVE-2021-21972VMware vCenter Server plugin path traversal leads to remote code executionThe vSphere Client (HTML5) in vCenter Server contains a path traversal flaw (CWE-22) in a plugin that allows an unauthenticated network attacker to u…KEVEPSS 100%analysed

Source: NIST National Vulnerability Database (record CVE-2015-2342), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.