cbcvebase.
CVE-2018-6978
published 2018-12-18

CVE-2018-6978: vRealize Operations (7.x before 7.0.0.11287810, 6.7.x before 6.7.0.11286837 and 6.6.x before 6.6.1.11286876) contains a local privilege escalation…

PriorityP428medium6.7CVSS 3.0
AVLACLPRHUINSUCHIHAH
EPSS
0.33%
25.3th percentile
vRealize Operations (7.x before 7.0.0.11287810, 6.7.x before 6.7.0.11286837 and 6.6.x before 6.6.1.11286876) contains a local privilege escalation vulnerability due to improper permissions of support scripts. Admin user of the vROps application with shell access may exploit this issue to elevate the privileges to root on a vROps machine. Note: the admin user (non-sudoer) should not be confused with root of the vROps machine.

Affected

3 ranges
VendorProductVersion rangeFixed in
vmwarevrealize_operations>= 6.6.0 < 6.6.1.112868766.6.1.11286876
vmwarevrealize_operations>= 6.7.0 < 6.7.0.112868376.7.0.11286837
vmwarevrealize_operations>= 7.0.0 < 7.0.0.112878107.0.0.11287810

CVSS provenance

nvdv3.06.7MEDIUMCVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.