CVE-2024-38813
17.09.2024, 18:15
The vCenter Server contains a privilege escalation vulnerability.A malicious actor with network access to vCenter Server may trigger this vulnerability to escalate privileges to root by sending a specially crafted network packet.Enginsight
Vendor | Product | Version |
---|---|---|
vmware | vcenter_server | 7.0 |
vmware | vcenter_server | 7.0:update1 |
vmware | vcenter_server | 7.0:update1a |
vmware | vcenter_server | 7.0:update1c |
vmware | vcenter_server | 7.0:update1d |
vmware | vcenter_server | 7.0:update2 |
vmware | vcenter_server | 7.0:update2a |
vmware | vcenter_server | 7.0:update2b |
vmware | vcenter_server | 7.0:update2c |
vmware | vcenter_server | 7.0:update2d |
vmware | vcenter_server | 7.0:update3 |
vmware | vcenter_server | 7.0:update3a |
vmware | vcenter_server | 7.0:update3c |
vmware | vcenter_server | 7.0:update3d |
vmware | vcenter_server | 7.0:update3e |
vmware | vcenter_server | 7.0:update3f |
vmware | vcenter_server | 7.0:update3g |
vmware | vcenter_server | 7.0:update3h |
vmware | vcenter_server | 7.0:update3i |
vmware | vcenter_server | 7.0:update3j |
vmware | vcenter_server | 7.0:update3k |
vmware | vcenter_server | 7.0:update3l |
vmware | vcenter_server | 7.0:update3m |
vmware | vcenter_server | 7.0:update3n |
vmware | vcenter_server | 8.0 |
vmware | vcenter_server | 8.0:update1 |
vmware | vcenter_server | 8.0:update1a |
vmware | vcenter_server | 8.0:update1b |
vmware | vcenter_server | 8.0:update1c |
vmware | vcenter_server | 8.0:update1d |
vmware | vcenter_server | 8.0:update1e |
vmware | vcenter_server | 8.0:update2 |
vmware | vcenter_server | 8.0:update2a |
vmware | vcenter_server | 8.0:update2b |
vmware | vcenter_server | 8.0:update2c |
vmware | vcenter_server | 8.0:update2d |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-250 - Execution with Unnecessary PrivilegesThe software performs an operation at a privilege level that is higher than the minimum level required, which creates new weaknesses or amplifies the consequences of other weaknesses.
- CWE-273 - Improper Check for Dropped PrivilegesThe software attempts to drop privileges but does not check or incorrectly checks to see if the drop succeeded.