EXPOSURES › CVE-2024-38813
CVE-2024-38813
HIGH ⌖ ON CISA KEV · EXPLOITEDVMware vCenter Server allows remote privilege escalation to root via a dropped privileges check bypass, enabling attackers to gain full control of the system.
This vulnerability allows an attacker with network access to escalate privileges to root by sending a specially crafted packet, bypassing the system's privilege checks. For DIB organizations, this poses a severe risk as vCenter is a critical component for managing virtualized infrastructure, and exploitation could lead to complete system compromise and data exfiltration. Organizations must immediately patch their vCenter instances and implement network segmentation to limit exposure.
Shame score — A critical privilege escalation vulnerability in a widely deployed virtualization management platform that allows remote code execution without requiring zero-day knowledge.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
VMware vCenter contains an improper check for dropped privileges vulnerability. This vulnerability could allow an attacker with network access to the vCenter Server to escalate privileges to root by sending a specially crafted packet.
| PRODUCT | STATUS |
|---|---|
| VMware Government Services (VGS) VMware, Inc. |
Authorized |
| Workspace ONE VMware, Inc. |
Authorized |