Database/Control plane, storage & DevOps
VMware vCenter Server (authenticated command execution via alarms): A user with permission to create or modify alarms
Impact
A user with permission to create or modify alarms and run script actions executes arbitrary commands on vCenter. The alarm/script-action feature is a legitimate automation path that doubles as a privilege-escalation route to root on the management server.
Who can reach it
Authenticated vCenter user holding alarm-management privileges - a role commonly granted to monitoring integrations.
What to do
Apply the Broadcom fix per advisory 25717. Also audit which service accounts hold alarm/script-action rights; most monitoring integrations do not need them.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.