Fixed Intel

CISA Known Exploited Vulnerability

This vulnerability is actively exploited in the wild and listed in the CISA Known Exploited Vulnerabilities catalog.

Remediation Deadline: Dec 11, 2024

CVE-2024-38813

High
EPSS 31.1%CISA KEV
VMware/vCenter Server

Description

VMware vCenter contains an improper check for dropped privileges vulnerability. This vulnerability could allow an attacker with network access to the vCenter Server to escalate privileges to root by sending a specially crafted packet.

EPSS — Exploit Probability

31.1%

Higher than 96.7% of all CVEs

Required Action

https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24968 ; https://nvd.nist.gov/vuln/detail/CVE-2024-38813

Risk Assessment

ELEVATED
In CISA KEV

Details

Severity
High
EPSS
31.1%
CISA KEV
Yes
Ransomware
Unknown
Articles
0

Timeline

Published

Nov 20, 2024

Added to KEV

Nov 20, 2024

Remediation Due

Dec 11, 2024

Affected Product

VMware

vCenter Server

View all VMware CVEs