CVE-2024-38813
The vCenter Server contains a privilege escalation vulnerability. A malicious actor with network access to vCenter Server may trigger this vulnerability to escalate privileges to root by sending a specially crafted network packet.
Scoring
- Severity
- HIGH
- CVSS base score
- 7.5
- CVSS vector
- CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS probability
- 17.36%
- CISA KEV
- Known exploited vulnerability
- CWE
- CWE-273, CWE-250
- Published
- 2024-09-17
- Last modified
- 2025-10-21
Affected products
- n/a VMware vCenter Server
- n/a VMware vCenter Server
- n/a VMware Cloud Foundation
- n/a VMware Cloud Foundation
Weakness type
Related vulnerabilities
- CVE-2025-1003 — HP Anyware Agent for Linux – Potential Authentication Bypass
- CVE-2026-21882 — theshit's Improper Privilege Dropping Allows Local Privilege Escalation via Command Re-execution
- CVE-2025-27396 — A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions < V4.0). Affected devices do
- CVE-2026-32107 — xrdp: Fail-open privilege drop in sesexec — child processes may execute as root if setuid fails
- CVE-2026-60085 — PraisonAI before 4.6.78 Unenforced Security Policy in Subprocess Sandbox
- CVE-2026-58086 — ktrace(2) privilege incorrectly validated in jails
- CVE-2026-54552 — sh _uid does not drop supplementary groups (incomplete privilege drop)
- CVE-2026-61897 — accountsservice: incomplete privilege drop when running Ubuntu-specific language helper scripts