7.8

CVE-2024-37081

The vCenter Server contains multiple local privilege escalation vulnerabilities due to misconfiguration of sudo. An authenticated local user with non-administrative privileges may exploit these issues to elevate privileges to root on vCenter Server Appliance.

Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
This information is available to logged-in users.
Daten sind bereitgestellt durch das CVE Programm von Authorized Data Publishers (ADP) (Unstrukturiert)
Vendorvmware
Product cloud_foundation
Default Statusunknown
Version < 6.0
Version 4.0
Status affected
Vendorvmware
Product vcenter_server
Default Statusunaffected
Version < 8.0u2d
Version 8.0
Status affected
Vendorvmware
Product vcenter_server
Default Statusunknown
Version < 7.0u3r
Version 7.0
Status affected
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 56.09% 0.98
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
security@vmware.com 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE-556 ASP.NET Misconfiguration: Use of Identity Impersonation

Configuring an ASP.NET application to run with impersonated credentials may give the application unnecessary privileges.