Permissions, Privileges, and Access Controls in vCenter Server - CVE-2024-37081
Published: June 18, 2024 / Updated: December 5, 2024
Vulnerability identifier: #VU92222
CSH Severity: Low
CVSS v4: 9.3 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H]
CVE-ID: CVE-2024-37081
CWE-ID: CWE-264
Exploitation vector: Local access
Exploit availability:
Public exploit is available
Vulnerability details
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to misconfiguration of sudo. A local user can execute arbitrary code with elevated privileges.
Affected software
vCenter Server
IBM Cloud Pak System
PowerProtect DP Series Appliance (IDPA)
Dell EMC VxRail Appliance
IBM Cloud Pak System
PowerProtect DP Series Appliance (IDPA)
Dell EMC VxRail Appliance
How to mitigate CVE-2024-37081
Install updates from vendor's website.
vCenter Server - addressed in versions 7.0 U3r, 8.0 U1e, 8.0 U2d
IBM Cloud Pak System - update to 2.3.4.1
PowerProtect DP Series Appliance (IDPA) - update to 2.7.7
Dell EMC VxRail Appliance - update to 8.0.213
IBM Cloud Pak System - update to 2.3.4.1
PowerProtect DP Series Appliance (IDPA) - update to 2.7.7
Dell EMC VxRail Appliance - update to 8.0.213