ZeroHour

CVE-2024-37081

CVSS 3.1
7.8 high
EPSS
5%p92
Published
()
Modified
Description

The vCenter Server contains multiple local privilege escalation vulnerabilities due to misconfiguration of sudo. An authenticated local user with non-administrative privileges may exploit these issues to elevate privileges to root on vCenter Server Appliance.

Vendors
vmware
Products
vcenter server, cloud foundation
Weakness
CWE-556
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news