60
CVE-2024-37081
—CVSS 3.1
7.8 high
EPSS
5%p92
Published
()
Modified
Description
The vCenter Server contains multiple local privilege escalation vulnerabilities due to misconfiguration of sudo. An authenticated local user with non-administrative privileges may exploit these issues to elevate privileges to root on vCenter Server Appliance.
- Vendors
- vmware
- Products
- vcenter server, cloud foundation
- Weakness
- CWE-556
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H