ZeroHour

CVE-2024-38813

KEVlarge1

Privilege Escalation to Root in VMware vCenter Server (CVE-2024-38813)

CISA: VMware vCenter Server Privilege Escalation Vulnerability

CVSS 3.1
9.8 critical
EPSS
17%p97
Published
()
KEV added
AI analysis

VMware vCenter Server contains a critical privilege escalation vulnerability that allows a malicious actor with network access to the server to escalate privileges to root by sending a specially crafted network packet. The CVSS vector (AV:N/AC:L/PR:N/UI:N) scores it as network-exploitable with no authentication or user interaction required, so any actor able to reach the vCenter interface, including from the internet if exposed, can attempt it. Successful exploitation yields root-level control of the vCenter appliance, which is the central management plane for VMware vSphere virtualization environments. Affected products in the source data are VMware vCenter Server and VMware Cloud Foundation; specific version ranges are not listed in the provided data and must be taken from the vendor advisory. CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2024-11-20, confirming active exploitation, and it was disclosed alongside the related, also actively exploited vCenter RCE CVE-2024-38812 in the same VMware fix release.

What to do: Upgrade vCenter Server and VMware Cloud Foundation to the fixed releases specified in VMware's advisory; the same advisory also patched the actively exploited RCE CVE-2024-38812, so confirm both are addressed. Until patched, restrict network access to the vCenter HTTPS interface from untrusted networks and prioritize remediation given the CISA KEV listing and 97th-percentile EPSS. Inventory deployed vCenter versions and check for signs of exploitation per vendor guidance.

Affected
VMware vCenter Server
VMware Cloud Foundation
Estimated exposure
largetens of thousands of internet-exposed vCenter servers per public internet-wide scans, with the total installed base likely in the hundreds of thousands — vCenter is the management appliance for VMware vSphere, the dominant enterprise virtualization platform, and public scan counts consistently show tens of thousands of vCenter web interfaces exposed to the internet, while most enterprise…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

The vCenter Server contains a privilege escalation vulnerability. A malicious actor with network access to vCenter Server may trigger this vulnerability to escalate privileges to root by sending a specially crafted network packet.

CISA Known Exploited Vulnerability
Affected
VMware vCenter Server
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
vmware
Products
cloud foundation, vcenter server
Weakness
CWE-250, CWE-273
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news