CRITICAL
CVE-2024-38813
CVSS
9.8
KEV
Description
The vCenter Server contains a privilege escalation vulnerability. A malicious actor with network access to vCenter Server may trigger this vulnerability to escalate privileges to root by sending a specially crafted network packet.
Summary dbcve.org
vCenter Server contains a privilege escalation vulnerability allowing a malicious actor with network access to escalate privileges to root by sending a specially crafted network packet. This critical flaw affects the core virtualization management platform and could allow complete system compromise.
Mitigation
Apply the VMware patch when available and restrict network access to vCenter Server to trusted networks only. Consider network segmentation and firewall rules to limit exposure.
Weakness (CWE)
CWE-250
CWE-273
EPSS Score
17.36%
Probability of exploitation in next 30 days
97th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.