CVE-2024-37081 is a local privilege escalation vulnerability affecting VMware vCenter Server and Cloud Foundation, stemming from sudo misconfigurations. An authenticated local user with non-administrative privileges can exploit this to gain root access. Rated 7.8 HIGH on CVSS, it poses a significant risk with low attack complexity and high impact on confidentiality, integrity, and availability. While not yet in CISA's KEV catalog, a Metasploit module exists, and it has garnered substantial community discussion and media coverage, indicating high interest and potential for future exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
8.0CPE matchmatch criteria | cpe:2.3:a:vmware:vcenter_server:8.0:-:*:*:*:*:*:* | ||
8.0CPE matchmatch criteria | cpe:2.3:a:vmware:vcenter_server:8.0:a:*:*:*:*:*:* | ||
8.0CPE matchmatch criteria | cpe:2.3:a:vmware:vcenter_server:8.0:b:*:*:*:*:*:* | ||
8.0CPE matchmatch criteria | cpe:2.3:a:vmware:vcenter_server:8.0:c:*:*:*:*:*:* | ||
8.0CPE matchmatch criteria | cpe:2.3:a:vmware:vcenter_server:8.0:update1:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.