cbcvebase.
CVE-2024-37081
published 2024-06-18

CVE-2024-37081: The vCenter Server contains multiple local privilege escalation vulnerabilities due to misconfiguration of sudo. An authenticated local user with…

PriorityP353high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EXPLOIT
EPSS
4.99%
91.3th percentile
The vCenter Server contains multiple local privilege escalation vulnerabilities due to misconfiguration of sudo. An authenticated local user with non-administrative privileges may exploit these issues to elevate privileges to root on vCenter Server Appliance.

Affected

3 ranges
VendorProductVersion rangeFixed in
vmwarecloud_foundation>= 4.0 < 5.25.2
vmwarevcenter_server
vmwarevcenter_server

Detection & IOCsextracted from sources · hover to see the quote

urlhttps://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/local/vcenter_sudo_lpe.rb
  • Target is VMware vCenter Server Appliance versions prior to 7.0.3 update R and 8.0.2 update D; exploitation requires an authenticated local non-administrative user escalating to root via misconfigured sudo rules.
  • Monitor for unexpected sudo executions on vCenter Server Appliance by non-administrative local accounts, particularly those resulting in root-level process spawning.
  • A public Metasploit module (exploits/linux/local/vcenter_sudo_lpe) exists for this CVE; presence of this module or its artifacts on a system should be treated as a high-fidelity indicator of exploitation attempt.
  • ·Exploitation requires an existing authenticated local session on the vCenter Server Appliance; this is a local privilege escalation, not a remote code execution vulnerability.
  • ·The Metasploit module was specifically tested against vCenter Server Appliance build 8.0.0.10000 20519528; detection and exploitation behaviour may differ on other builds or patch levels.
  • ·CVE-2024-37081 is one of multiple related vCenter vulnerabilities (alongside CVE-2024-37079 and CVE-2024-37080); the latter two are heap-overflow/RCE issues and should not be conflated with this LPE.
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.