TROYANOSYVIRUS
Back to CVEs

CVE-2024-38813

HIGHCISA KEV
7.5

Description

The vCenter Server contains a privilege escalation vulnerability. A malicious actor with network access to vCenter Server may trigger this vulnerability to escalate privileges to root by sending a specially crafted network packet.

CVE Details

CVSS v3.1 Score7.5
SeverityHIGH
CVSS VectorCVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack VectorNETWORK
ComplexityHIGH
Privileges RequiredLOW
User InteractionNONE
Published9/17/2024
Last Modified10/31/2025
Sourcekev
Honeypot Sightings0

CISA KEV

VendorVMware
ProductvCenter Server
Vulnerability NameVMware vCenter Server Privilege Escalation Vulnerability
KEV Date Added2024-11-20
Remediation Due Date2024-12-11
Ransomware UseUnknown

Affected Products

vmware:cloud_foundationvmware:vcenter_server

Weaknesses (CWE)

CWE-250CWE-273CWE-273

IOC Correlations

No correlations recorded

This product uses data from the NVD API but is not endorsed or certified by the NVD.