CVE-2024-37081
published 2024-06-18CVE-2024-37081: The vCenter Server contains multiple local privilege escalation vulnerabilities due to misconfiguration of sudo. An authenticated local user with…
PriorityP353high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EXPLOIT
EPSS
4.99%
91.3th percentile
The vCenter Server contains multiple local privilege escalation vulnerabilities due to misconfiguration of sudo. An authenticated local user with non-administrative privileges may exploit these issues to elevate privileges to root on vCenter Server Appliance.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| vmware | cloud_foundation | >= 4.0 < 5.2 | 5.2 |
| vmware | vcenter_server | — | — |
| vmware | vcenter_server | — | — |
Detection & IOCsextracted from sources · hover to see the quote
urlhttps://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/local/vcenter_sudo_lpe.rb↗
- →Target is VMware vCenter Server Appliance versions prior to 7.0.3 update R and 8.0.2 update D; exploitation requires an authenticated local non-administrative user escalating to root via misconfigured sudo rules. ↗
- →Monitor for unexpected sudo executions on vCenter Server Appliance by non-administrative local accounts, particularly those resulting in root-level process spawning. ↗
- →A public Metasploit module (exploits/linux/local/vcenter_sudo_lpe) exists for this CVE; presence of this module or its artifacts on a system should be treated as a high-fidelity indicator of exploitation attempt. ↗
- ·Exploitation requires an existing authenticated local session on the vCenter Server Appliance; this is a local privilege escalation, not a remote code execution vulnerability. ↗
- ·The Metasploit module was specifically tested against vCenter Server Appliance build 8.0.0.10000 20519528; detection and exploitation behaviour may differ on other builds or patch levels. ↗
- ·CVE-2024-37081 is one of multiple related vCenter vulnerabilities (alongside CVE-2024-37079 and CVE-2024-37080); the latter two are heap-overflow/RCE issues and should not be conflated with this LPE. ↗
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
2024-06-18
Published