CVE-2024-38813
KEVlarge1Privilege Escalation to Root in VMware vCenter Server (CVE-2024-38813)
CISA: VMware vCenter Server Privilege Escalation Vulnerability
VMware vCenter Server contains a critical privilege escalation vulnerability that allows a malicious actor with network access to the server to escalate privileges to root by sending a specially crafted network packet. The CVSS vector (AV:N/AC:L/PR:N/UI:N) scores it as network-exploitable with no authentication or user interaction required, so any actor able to reach the vCenter interface, including from the internet if exposed, can attempt it. Successful exploitation yields root-level control of the vCenter appliance, which is the central management plane for VMware vSphere virtualization environments. Affected products in the source data are VMware vCenter Server and VMware Cloud Foundation; specific version ranges are not listed in the provided data and must be taken from the vendor advisory. CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2024-11-20, confirming active exploitation, and it was disclosed alongside the related, also actively exploited vCenter RCE CVE-2024-38812 in the same VMware fix release.
What to do: Upgrade vCenter Server and VMware Cloud Foundation to the fixed releases specified in VMware's advisory; the same advisory also patched the actively exploited RCE CVE-2024-38812, so confirm both are addressed. Until patched, restrict network access to the vCenter HTTPS interface from untrusted networks and prioritize remediation given the CISA KEV listing and 97th-percentile EPSS. Inventory deployed vCenter versions and check for signs of exploitation per vendor guidance.
| VMware vCenter Server | — |
| VMware Cloud Foundation | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
The vCenter Server contains a privilege escalation vulnerability. A malicious actor with network access to vCenter Server may trigger this vulnerability to escalate privileges to root by sending a specially crafted network packet.
- Affected
- VMware vCenter Server
- Required action
- Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
- Due date
- Ransomware use
- Unknown
- Vendors
- vmware
- Products
- cloud foundation, vcenter server
- Weakness
- CWE-250, CWE-273
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H