Executive brief
VMware vCenter Server contains a privilege escalation vulnerability due to an improper check for dropped privileges. A malicious actor with network access can escalate privileges to root by sending a specially crafted network packet.
Affected products
- VMware vCenter Server 7.0, 8.0
Timeline
- 2024-11-20: disclosed
- 2024-11-20: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2024-11-20: advisory: Broadcom/VMware published security advisory