CVE-2024-38813
published 2024-09-17CVE-2024-38813: The vCenter Server contains a privilege escalation vulnerability. A malicious actor with network access to vCenter Server may trigger this vulnerability to…
PriorityP192critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2024-12-11
Exploited in the wild
EPSS
16.68%
96.7th percentile
The vCenter Server contains a privilege escalation vulnerability. A malicious actor with network access to vCenter Server may trigger this vulnerability to escalate privileges to root by sending a specially crafted network packet.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| vmware | cloud_foundation | >= 4.0 < 5.2 | 5.2 |
| vmware | vcenter_server | — | — |
| vmware | vcenter_server | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Detect exploitation attempts by monitoring for specially crafted network packets sent to vCenter Server's DCE/RPC protocol implementation targeting privilege escalation to root ↗
- →CVE-2024-38813 is confirmed exploited in the wild — treat any unpatched vCenter Server with network-accessible management interfaces as actively targeted ↗
- →Alert on any vCenter Server process gaining root privileges via network-initiated requests; this vulnerability requires no authentication and no user interaction ↗
- ·The initial September 17, 2024 patches did NOT fully remediate CVE-2024-38812 (the companion RCE); ensure patching targets the updated releases: vCenter Server 8.0 U3d, 8.0 U2e, and 7.0 U3t ↗
- ·No workarounds exist for CVE-2024-38813; patching is the only remediation. Strictly control network perimeter access to vSphere management components as a temporary measure only ↗
- ·vSphere 6.5 and 6.7 are confirmed impacted but will NOT receive security updates due to end-of-support status ↗
- ·CISA remediation due date was 2024-12-11; reference Broadcom advisory https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24968 for the authoritative patch response matrix ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vulncheck7.5HIGH
cisa9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA
VMware vCenter Server Privilege Escalation Vulnerability
cisa·2024-11-20·CVSS 9.8
CVE-2024-38813 [CRITICAL] CWE-250 VMware vCenter Server Privilege Escalation Vulnerability
Vulnerability: VMware vCenter Server Privilege Escalation Vulnerability
Affected: VMware vCenter Server
VMware vCenter contains an improper check for dropped privileges vulnerability. This vulnerability could allow an attacker with network access to the vCenter Server to escalate privileges to root by sending a specially crafted packet.
Required Action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Notes: https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24968 ; https://nvd.nist.gov/vuln/detail/CVE-2024-38813
Remediation Due Date: 2024-12-11
GHSA
GHSA-66vj-hxh5-x3jh: The vCenter Server contains a privilege escalation vulnerability
ghsa_unreviewed·2024-09-17
CVE-2024-38813 [HIGH] CWE-250 GHSA-66vj-hxh5-x3jh: The vCenter Server contains a privilege escalation vulnerability
The vCenter Server contains a privilege escalation vulnerability. A malicious actor with network access to vCenter Server may trigger this vulnerability to escalate privileges to root by sending a specially crafted network packet.
VulnCheck
VMware vCenter Server Privilege Escalation Vulnerability
vulncheck·2024·CVSS 7.5
CVE-2024-38813 [HIGH] CWE-250 VMware vCenter Server Privilege Escalation Vulnerability
VMware vCenter Server Privilege Escalation Vulnerability
VMware vCenter contains an improper check for dropped privileges vulnerability. This vulnerability could allow an attacker with network access to the vCenter Server to escalate privileges to root by sending a specially crafted packet.
Affected: VMware vCenter Server
Required Action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Exploitation References: https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24968; https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json; https://isc.sans.edu/diary/Vulnerability+Symbiosis+vSpheres+CVE202438812+and+CVE202438813+Guest+Diary/31510/; https://info.g
No detection rules found.
No public exploits indexed.
Bleepingcomputer
Broadcom fixes high-severity VMware NSX bugs reported by NSA
blogs_bleepingcomputer·2025-09-30·CVSS 9.3
CVE-2025-41251 [CRITICAL] Broadcom fixes high-severity VMware NSX bugs reported by NSA
## Broadcom fixes high-severity VMware NSX bugs reported by NSA
## Sergiu Gatlan
Broadcom has released security updates to patch two high-severity VMware NSX vulnerabilities reported by the U.S. National Security Agency (NSA).
VMware NSX is a networking virtualization solution within VMware Cloud Foundation that enables administrators to deploy traditional and modern applications in private/hybrid clouds.
The first security flaw reported by the NSA, tracked as CVE-2025-41251 , is due to a weakness in the password recovery mechanism that can let unauthenticated attackers enumerate valid usernames, which could later be used in brute-force attacks.
The second one ( CVE-2025-41252 ) is a username enumeration vulnerability that unauthenticated threat actors can also exploit to enumerate va
Qualys
Inside LockBit: Defense Lessons from the Leaked LockBit Negotiations | Qualys
blogs_qualys·2025-05-08
Inside LockBit: Defense Lessons from the Leaked LockBit Negotiations | Qualys
#### Table of Contents
- Who is LockBit? How it Evolved and Operates
- Monero: The Coin of the Realm
- Patch or Mitigate Now: Critical CVEs Exploited by LockBit
- Beyond Traditional Endpoints: Other Compromised Systems
- Initial Access and Deployment
- Conclusion
The LockBit ransomware gang recently suffered a significant data breach. Their dark web affiliate panels were defaced with the message “Don’t do crime CRIME IS BAD xoxo from Prague,” linking to a MySQL database dump. This archive contains a SQL file from LockBit’s affiliate panel database that includes twenty tables, notably including a ‘btc_addresses’ table with 59,975 unique bitcoin addresses and a ‘chats’ table containing over 4,400 victim negotiation messages from December 2024 to the end of April 2025.
This blog post will
Qualys
Inside LockBit: Defense Lessons from the Leaked LockBit Negotiations
blogs_qualys·2025-05-08
Inside LockBit: Defense Lessons from the Leaked LockBit Negotiations
## Table of Contents
Who is LockBit? How it Evolved and Operates
Monero: The Coin of the Realm
Patch or Mitigate Now: Critical CVEs Exploited by LockBit
Beyond Traditional Endpoints: Other Compromised Systems
Initial Access and Deployment
Conclusion
The LockBit ransomware gang recently suffered a significant data breach. Their dark web affiliate panels were defaced with the message “Don’t do crime CRIME IS BAD xoxo from Prague,” linking to a MySQL database dump. This archive contains a SQL file from LockBit’s affiliate panel database that includes twenty tables, notably including a ‘btc_addresses’ table with 59,975 unique bitcoin addresses and a ‘chats’ table containing over 4,400 victim negotiation messages from December 2024 to the end of April 2025.
This blog post will leverage
Bleepingcomputer
Broadcom fixes three VMware zero-days exploited in attacks
blogs_bleepingcomputer·2025-03-04·CVSS 9.8
CVE-2025-22224 [CRITICAL] Broadcom fixes three VMware zero-days exploited in attacks
## Broadcom fixes three VMware zero-days exploited in attacks
## Sergiu Gatlan
"This is a situation where an attacker who has already compromised a virtual machine's guest OS and gained privileged access (administrator or root) could move into the hypervisor itself," the company explained today. "Broadcom has information to suggest that exploitation of these issues has occurred 'in the wild'."
Broadcom says CVE-2025-22224 is a critical-severity VCMI heap overflow vulnerability that enables local attackers with administrative privileges on the targeted VM to execute code as the VMX process running on the host.
CVE-2025-22225 is an ESXi arbitrary write vulnerability that allows the VMX process to trigger arbitrary kernel writes, leading to a sandbox escape, while CVE-2025-22226 is descri
Bleepingcomputer
Critical RCE bug in VMware vCenter Server now exploited in attacks
blogs_bleepingcomputer·2024-11-18·CVSS 9.8
CVE-2024-38812 [CRITICAL] Critical RCE bug in VMware vCenter Server now exploited in attacks
## Critical RCE bug in VMware vCenter Server now exploited in attacks
## Sergiu Gatlan
Broadcom warned today that attackers are now exploiting two VMware vCenter Server vulnerabilities, one of which is a critical remote code execution flaw.
TZL security researchers reported the RCE vulnerability ( CVE-2024-38812 ) during China's 2024 Matrix Cup hacking contest. It is caused by a heap overflow weakness in the vCenter's DCE/RPC protocol implementation and affects products containing vCenter, including VMware vSphere and VMware Cloud Foundation.
The other vCenter Server flaw now exploited in the wild (reported by the same researchers) is a privilege escalation flaw tracked as CVE-2024-38813 that enables attackers to escalate privileges to root with a specially crafted network packet.
"U
Checkpoint
28th October – Threat Intelligence Report
blogs_checkpoint·2024-10-28
CVE-2024-20481 28th October – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 28th October – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 28th October, please download our Threat Intelligence Bulletin .
TOP ATTACKS AND BREACHES
Grupo Aeroportuario del Centro Norte (OMA), operator of 13 airports across Mexico, was hacked by the RansomHub ransomware gang, who threatened to leak 3TB of stolen data unless a ransom is paid. The attack disrupted terminal information screens and forced OMA to activate backup systems, with no reported material adverse e
Bleepingcomputer
VMware fixes bad patch for critical vCenter Server RCE flaw
blogs_bleepingcomputer·2024-10-22·CVSS 9.8
CVE-2024-38812 [CRITICAL] VMware fixes bad patch for critical vCenter Server RCE flaw
## VMware fixes bad patch for critical vCenter Server RCE flaw
## Bill Toulas
VMware has released another security update for CVE-2024-38812, a critical VMware vCenter Server remote code execution vulnerability that was not correctly fixed in the first patch from September 2024.
The flaw is rated critical (CVSS v3.1 score: 9.8) and stems from a heap overflow weakness in vCenter's DCE/RPC protocol implementation, impacting the vCenter Server and any products incorporating it, such as vSphere and Cloud Foundation.
The flaw does not require user interaction for exploitation, as remote code execution is triggered when a specially crafted network packet is received.
The vulnerability was discovered and used by TZL security researchers during China's 2024 Matrix Cup hacking contest. The res
Checkpoint
23rd September – Threat Intelligence Report
blogs_checkpoint·2024-09-23
CVE-2024-8897 23rd September – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 23rd September – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 23rd September, please download our Threat Intelligence Bulletin .
TOP ATTACKS AND BREACHES
Medusa ransomware gang has claimed responsibility for an attack on the Providence Public School District (PPSD) in Rhode Island. The school district is still grappling with ongoing internet outages since September 11, impacting over 20,000 students across 37 schools. While the district has contacted law enforcement an
Bleepingcomputer
Broadcom fixes critical RCE bug in VMware vCenter Server
blogs_bleepingcomputer·2024-09-17·CVSS 9.8
CVE-2024-38812 [CRITICAL] Broadcom fixes critical RCE bug in VMware vCenter Server
## Broadcom fixes critical RCE bug in VMware vCenter Server
## Sergiu Gatlan
Broadcom has fixed a critical VMware vCenter Server vulnerability that attackers can exploit to gain remote code execution on unpatched servers via a network packet.
vCenter Server is the central management hub for VMware's vSphere suite, helping administrators manage and monitor virtualized infrastructure.
The vulnerability ( CVE-2024-38812 ), reported by TZL security researchers during China's 2024 Matrix Cup hacking contest, is caused by a heap overflow weakness in vCenter's DCE/RPC protocol implementation. It also affects products containing vCenter, including VMware vSphere and VMware Cloud Foundation.
Unauthenticated attackers can exploit it remotely in low-complexity attacks that don't require user int
2024-09-17
Published
2024-11-20
Added to CISA KEV
Exploited in the wild