Vulnerability Intelligence Report
Privilege escalation vulnerability
CVE-2024-38813
The vCenter Server contains a privilege escalation vulnerability. A malicious actor with network access to vCenter Server may trigger this vulnerability to escalate privileges to root by sending a specially crafted network packet.
CISA KEV
SSVC: Active Exploitation
CVSS Base Score
7.5
HIGH
Exploitability:1.7
Impact Score:5.9
EPSS Probability:16.68%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-273 ↗CWE-273 Improper Check for Dropped Privileges
CWE-250 ↗CWE-250
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| vmware | cloud_foundation | all |
| vmware | vcenter_server | 7.0, 8.0 |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | VMware by Broadcom · Vendor · USA |
| Reserved | 2024-06-19T22:31:57 |
| Published | 2024-09-17T17:13:13 |
| Patch Date | 2024-09-17 |
| Last Updated | 2025-10-21T22:55:44 |
Community Chatter & Buzz