Junglewise Threat Intelligence

CVE-2024-38813: VMware vCenter Server Privilege Escalation Vulnerability

CVE-2024-38813 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2024-11-20

Technologies: Broadcom vCenter Server, VMware Cloud Foundation. Vendors: Broadcom, VMware.

Executive brief

VMware vCenter Server contains a privilege escalation vulnerability due to an improper check for dropped privileges. A malicious actor with network access can escalate privileges to root by sending a specially crafted network packet.

Affected products

  • VMware vCenter Server 7.0, 8.0

Timeline

  • 2024-11-20: disclosed
  • 2024-11-20: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2024-11-20: advisory: Broadcom/VMware published security advisory

Related threats