CVSS v3.1 Metrics
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Prediction
Documented as more likely to be exploited than 96.5% of known CVEs.
Nov 20, 2024
Dec 11, 2024
Threat Analysis
VMware vCenter contains an improper check for dropped privileges vulnerability. This vulnerability could allow an attacker with network access to the vCenter Server to escalate privileges to root by sending a specially crafted packet.
Remediation Directive
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
External Intelligence
https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24968
https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24968
National Vulnerability Database
https://nvd.nist.gov/vuln/detail/CVE-2024-38813