Database/Kernel, userspace & hypervisor
VMware vCenter: Privilege escalation to root on vCenter via a crafted network packet
CVSS 7.5CVE-2024-38813Kernel, userspace & hypervisorKnown exploitedcurated
Impact
Privilege escalation to root on vCenter via a crafted network packet [KEV]
Who can reach it
Network access to the management plane
What to do
vCenter patch + service restart
References
Related entries
- VMware vCenter: Out-of-bounds write in the DCERPC implementation - unauthenticated remote code executionCVE-2023-34048 · VMware vCenterCritical
- VMware vCenter: Heap overflow in the DCERPC implementation - unauthenticated remote code execution on vCenterCVE-2024-37079 · VMware vCenterCritical
- VMware vCenter: Heap overflow in DCERPC - unauthenticated remote code execution on vCenterCVE-2024-38812 · VMware vCenterCritical
- Linux kernel NVMe target core (controller teardown racing queue-pair establishment): An initiator that disconnectsCVE-2024-42152 · Linux kernel NVMe target core (controller teardown racing queue-pair establishment)High
- Linux kernel NVMe-oF TCP target (nvmet-tcp queue command allocation failure): When command allocation for a new queueCVE-2024-46737 · Linux kernel NVMe-oF TCP target (nvmet-tcp queue command allocation failure)High
- Linux kernel SMC (CLC message drain loop, unchecked sock_recvmsg return): The length field in the CLC header isCVE-2024-57791 · Linux kernel SMC (CLC message drain loop, unchecked sock_recvmsg return)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.