cve-2024-38813

HIGH CVSS 7.5 cisa_known_exploited
Description

VMware vCenter contains an improper check for dropped privileges vulnerability. This vulnerability could allow an attacker with network access to the vCenter Server to escalate privileges to root by sending a specially crafted packet.

Timeline
Published
2024-11-20
Last Modified
2024-11-20
CVSS Details

CVSS details not available.

Affected Products

No product information available.

References

No references available.

Linked Vulnerabilities

No linked vulnerabilities found.

{
  "cvss": 7.5,
  "datePublished": "2024-11-20",
  "dateUpdated": "2024-11-20",
  "description": "VMware vCenter contains an improper check for dropped privileges vulnerability. This vulnerability could allow an attacker with network access to the vCenter Server to escalate privileges to root by sending a specially crafted packet.",
  "dueDate": "2024-12-11",
  "id": "CVE-2024-38813",
  "kev_catalogs": [
    "cisa"
  ],
  "knownRansomwareCampaignUse": "Unknown",
  "notes": "https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24968 ; https://nvd.nist.gov/vuln/detail/CVE-2024-38813",
  "product": "vCenter Server",
  "requiredAction": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
  "severity": "HIGH",
  "source": "cisa_known_exploited",
  "title": "VMware vCenter Server Privilege Escalation Vulnerability",
  "vendor": "VMware"
}
View JSON API Download JSON