CVE-2024-37087
- EPSS 0.64%
- Veröffentlicht 25.06.2024 15:15:12
- Zuletzt bearbeitet 27.06.2025 13:39:54
The vCenter Server contains a denial-of-service vulnerability. A malicious actor with network access to vCenter Server may create a denial-of-service condition.
CVE-2024-37079
- EPSS 82.81%
- Veröffentlicht 18.06.2024 06:15:11
- Zuletzt bearbeitet 26.01.2026 14:52:05
vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger this vulnerability by sending a specially crafted network packet potentially leadi...
CVE-2024-37081
- EPSS 50.28%
- Veröffentlicht 18.06.2024 06:15:11
- Zuletzt bearbeitet 21.11.2024 09:23:09
The vCenter Server contains multiple local privilege escalation vulnerabilities due to misconfiguration of sudo. An authenticated local user with non-administrative privileges may exploit these issues to elevate privileges to root on vCenter Server A...
CVE-2024-22274
- EPSS 63.47%
- Veröffentlicht 21.05.2024 18:15:09
- Zuletzt bearbeitet 27.06.2025 13:37:52
The vCenter Server contains an authenticated remote code execution vulnerability. A malicious actor with administrative privileges on the vCenter appliance shell may exploit this issue to run arbitrary commands on the underlying operating system.
CVE-2024-22275
- EPSS 11.68%
- Veröffentlicht 21.05.2024 18:15:09
- Zuletzt bearbeitet 27.06.2025 13:38:06
The vCenter Server contains a partial file read vulnerability. A malicious actor with administrative privileges on the vCenter appliance shell may exploit this issue to partially read arbitrary files containing sensitive data.
CVE-2024-22273
- EPSS 0.3%
- Veröffentlicht 21.05.2024 18:15:08
- Zuletzt bearbeitet 26.03.2025 16:15:19
The storage controllers on VMware ESXi, Workstation, and Fusion have out-of-bounds read/write vulnerability. A malicious actor with access to a virtual machine with storage controllers enabled may exploit this issue to create a denial of service cond...
CVE-2024-22254
- EPSS 0.41%
- Veröffentlicht 05.03.2024 18:15:48
- Zuletzt bearbeitet 07.05.2025 15:37:28
VMware ESXi contains an out-of-bounds write vulnerability. A malicious actor with privileges within the VMX process may trigger an out-of-bounds write leading to an escape of the sandbox.
CVE-2024-22255
- EPSS 4.35%
- Veröffentlicht 05.03.2024 18:15:48
- Zuletzt bearbeitet 07.05.2025 15:37:25
VMware ESXi, Workstation, and Fusion contain an information disclosure vulnerability in the UHCI USB controller. A malicious actor with administrative access to a virtual machine may be able to exploit this issue to leak memory from the vmx process. ...
CVE-2024-22253
- EPSS 0.08%
- Veröffentlicht 05.03.2024 18:15:47
- Zuletzt bearbeitet 07.05.2025 15:35:46
VMware ESXi, Workstation, and Fusion contain a use-after-free vulnerability in the UHCI USB controller. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX pr...
CVE-2024-22235
- EPSS 0.05%
- Veröffentlicht 21.02.2024 05:15:08
- Zuletzt bearbeitet 20.03.2025 20:15:31
VMware Aria Operations contains a local privilege escalation vulnerability. A malicious actor with administrative access to the local system can escalate privileges to 'root'.