CVE-2024-38813

Published Sep 17, 2024

Last updated 3 months ago

Overview

Description
The vCenter Server contains a privilege escalation vulnerability. A malicious actor with network access to vCenter Server may trigger this vulnerability to escalate privileges to root by sending a specially crafted network packet.
Source
security@vmware.com
NVD status
Analyzed

Risk scores

CVSS 3.1

Type
Primary
Base score
9.8
Impact score
5.9
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity
CRITICAL

Known exploits

Data from CISA

Vulnerability name
VMware vCenter Server Privilege Escalation Vulnerability
Exploit added on
Nov 20, 2024
Exploit action due
Dec 11, 2024
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Weaknesses

security@vmware.com
CWE-250
nvd@nist.gov
CWE-273

Social media

Hype score
Not currently trending
  1. Vulnerability Symbiosis: vSphere?s CVE-2024-38812 and CVE-2024-38813 [Guest Diary], (Wed, Dec 11th) https://t.co/dusqWtiurl

    @itsecuritynewsl

    11 Dec 2024

    15 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. Vulnerability Symbiosis: vSphere’s CVE-2024-38812 and CVE-2024-38813 [Guest Diary] https://t.co/GkbDZpwgHD https://t.co/56Z68KYQuD

    @sans_isc

    11 Dec 2024

    1618 Impressions

    2 Retweets

    4 Likes

    1 Bookmark

    0 Replies

    0 Quotes

  3. 🚨 Critical VMware vCenter Server Vulnerabilities 🚨 Two serious vulnerabilities (CVE-2024-38812 & CVE-2024-38813) in VMware vCenter Server are currently being actively exploited. These flaws enable attackers to execute arbitrary code and escalate privileges, putting enterpr

    @AladdinCyberae

    2 Dec 2024

    41 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. 3/10 🚨 @VMware 's vCenter Server vulnerabilities (CVE-2024-38812 & CVE-2024-38813) are in the wild. Ensure your systems are updated by December 11, 2024. #VulnerabilityAlert #VirtualizationSecurity

    @Eth1calHackrZ

    25 Nov 2024

    21 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. Happy Friday! This week, we spotlight critical vulnerabilities in #VMware vCenter Server, recently exploited in active attacks: a critical remote code execution vulnerability (CVE-2024-38812) and a privilege escalation flaw (CVE-2024-38813), impacting products like VMware vSphere

    @vali_cyber

    22 Nov 2024

    47 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. CVE-2024-38813 is getting exploited #inthewild. Find out more at https://t.co/zNunqRnweA CVE-2024-38812 is getting exploited #inthewild. Find out more at https://t.co/hCViVKqL3t CVE-2024-44309 is getting exploited #inthewild. Find out more at https://t.co/C8QQNSrZvs

    @inthewildio

    22 Nov 2024

    75 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  7. CISA Adds Two Known Exploited Vulnerabilities to Catalog: CVE-2024-38812 - VMware vCenter Server Heap-Based Buffer Overflow CVE-2024-38813 - VMware vCenter Server Privilege Escalation https://t.co/fG5YkHFygH https://t.co/YR4uqrWw8j

    @TMJIntel

    21 Nov 2024

    36 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  8. Critical RCE vulnerability (CVE-2024-38812) in VMware vCenter Server is being exploited in the wild. Disclosed at China's Matrix Cup, the flaw stems from a heap overflow in DCE/RPC. A related privilege escalation flaw (CVE-2024-38813) is also active. Admins urged to patch ASAP! h

    @ishowcybersec

    20 Nov 2024

    87 Impressions

    1 Retweet

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  9. Latest Known Exploited Vulnerabilities (#KEV) : #CVE-2024-38813 #VMware vCenter Server Privilege Escalation Vulnerability https://t.co/m09zP7NZos

    @ScyScan

    20 Nov 2024

    37 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  10. 🛡️ We added #VMware #vCenter Server vulnerabilities, CVE-2024-38812 & CVE-2024-38813, to our Known Exploited Vulnerabilities Catalog. Visit https://t.co/myxOwap1Tf & apply mitigations to protect your org from cyberattacks. #Cybersecurity #InfoSec https://t.co/AYUTnspztf

    @CISACyber

    20 Nov 2024

    5896 Impressions

    24 Retweets

    52 Likes

    4 Bookmarks

    0 Replies

    2 Quotes

  11. 🚨 VMware confirms active exploits for CVE-2024-38812 & CVE-2024-38813! Critical RCE & privilege escalation flaws in vCenter Server. Patch now, restrict access, & monitor activity. Details: https://t.co/Bg35n19WOM #CyberSecurity #VMware

    @VulnVanguard

    20 Nov 2024

    44 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  12. Broadcom repatched VMware bugs for the second time #VMware #Broadcom #CVE-2024-38812 #CVE-2024-38813 https://t.co/bqKOi1HCAy

    @pravin_karthik

    19 Nov 2024

    47 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  13. Major security flaws in Progress Kemp LoadMaster (CVE-2024-1212) and VMware vCenter Server (CVE-2024-38812 and CVE-2024-38813) are actively being exploited. Learn how to mitigate this flaw and secure your system before it’s too late – Read more: https://t.co/6dz5iY251w #infosec

    @TheHackersNews

    19 Nov 2024

    37079 Impressions

    31 Retweets

    74 Likes

    10 Bookmarks

    1 Reply

    3 Quotes

  14. Actively Exploited VMware Vulnerabilities (CVE-2024-38812 & CVE-2024-38813) Threaten Virtualized Infrastructure https://t.co/hgbd9TIzmd

    @Dinosn

    19 Nov 2024

    4274 Impressions

    16 Retweets

    47 Likes

    8 Bookmarks

    1 Reply

    0 Quotes

  15. Critical RCE bug in VMware vCenter Server now exploited in attacks: https://t.co/s1Po0Z81VT Attackers are exploiting two critical vulnerabilities in VMware vCenter Server: CVE-2024-38812, a remote code execution flaw, and CVE-2024-38813, a privilege escalation flaw. Both were… h

    @securityRSS

    19 Nov 2024

    24 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  16. VMware vCenter Serverの重大(Critical)な遠隔コード実行脆弱性、CVE-2024-38812が実際に攻撃されだした。DCE/RPCプロトコルの実装に起因するヒープベースのバッファオーバーフローで、中国のハッキングコンテストMatrix Cupが初出。権限昇格のCVE-2024-38813も悪用。 https://t.co/GTNtYb7XlK

    @__kokumoto

    18 Nov 2024

    4185 Impressions

    15 Retweets

    40 Likes

    8 Bookmarks

    1 Reply

    1 Quote

  17. "VMware by Broadcom confirmed that exploitation has occurred in the wild for CVE-2024-38812 and CVE-2024-38813." ^ Bug first exploited at China Matrix Cup hacker contest in June. Back story here https://t.co/kONRPv6Juh

    @ryanaraine

    18 Nov 2024

    5775 Impressions

    13 Retweets

    37 Likes

    11 Bookmarks

    0 Replies

    2 Quotes

  18. Vulnerability Research team at https://t.co/1FrIpw4ix3 has proved the exploitability of CVE-2024-38812 and CVE-2024-38813 which are critical vulnerabilities in VMware vCenter. https://t.co/M5kByFmsDq

    @pppturtle

    17 Nov 2024

    4303 Impressions

    11 Retweets

    56 Likes

    24 Bookmarks

    0 Replies

    0 Quotes

  19. VMware məhsullarında boşluq (CVE-2024-38813) aşkar olunub. #ETX #certaz #cybersecurity #kibertəhlükəsizlik #xəbərdarlıq https://t.co/7wVzUygTCP

    @CERTAzerbaijan

    28 Oct 2024

    32 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  20. Broadcom releases patches for critical VMware vCenter Server vulnerabilities (CVE-2024-38812, CVE-2024-38813). CVE-2024-38812 (CVSS 9.8) allows remote code execution in versions 7.0, 8.0 & Cloud Foundation. Immediate patching is recommended. #cve #infosec #broadcom #vm #rc

    @paramdhagia

    22 Oct 2024

    39 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  21. VMware vCenter Server Vulnerabilities Let Attackers Execute Remote Code: https://t.co/2lFo9hpG1D Broadcom released critical updates for VMware vCenter Server to address vulnerabilities CVE-2024-38812 and CVE-2024-38813, which allow remote code execution and privilege escalation,

    @securityRSS

    22 Oct 2024

    37 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  22. VMware fixes critical vCenter Server RCE bug – again! (CVE-2024-38812): Broadcom has released new patches for previously fixed vulnerabilities (CVE-2024-38812, CVE-2024-38813) in vCenter Server, one of which hasn’t been fully addressed the first time and… https://t.co/rm9ZBcvsUf

    @cipherstorm

    22 Oct 2024

    52 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  23. VMware fixes critical vCenter Server RCE bug – again! (CVE-2024-38812): Broadcom has released new patches for previously fixed vulnerabilities (CVE-2024-38812, CVE-2024-38813) in vCenter Server, one of which hasn’t been fully addressed the first time and… https://t.co/6J6D2cdLbt

    @shah_sheikh

    22 Oct 2024

    46 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

Configurations