7.8

CVE-2024-37081

The vCenter Server contains multiple local privilege escalation vulnerabilities due to misconfiguration of sudo. An authenticated local user with non-administrative privileges may exploit these issues to elevate privileges to root on vCenter Server Appliance.
Daten sind bereitgestellt durch das CVE Programm von Authorized Data Publishers (ADP) (Unstrukturiert)
Herstellervmware
Produkt cloud_foundation
Default Statusunknown
Version 4.0
Version < 6.0
Status affected
Herstellervmware
Produkt vcenter_server
Default Statusunaffected
Version 8.0
Version < 8.0u2d
Status affected
Herstellervmware
Produkt vcenter_server
Default Statusunknown
Version 7.0
Version < 7.0u3r
Status affected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 49.87% 0.978
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
security@vmware.com 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE-556 ASP.NET Misconfiguration: Use of Identity Impersonation

Configuring an ASP.NET application to run with impersonated credentials may give the application unnecessary privileges.