Skip to main content

CVE-2024-38813

7.5
HIGHCVSS v3.1 Base Score
29.53%
LOW RiskEPSS (97th percentile)
KEV

The vCenter Server contains a privilege escalation vulnerability. A malicious actor with network access to vCenter Server may trigger this vulnerability to escalate privileges to root by sending a specially crafted network packet.

Published: 9/17/2024
Modified: 10/31/2025
Back to CVE Lookup

ACTIVELY EXPLOITED IN THE WILD

This vulnerability is listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.

Vulnerability Name:

VMware vCenter Server Privilege Escalation Vulnerability

Vendor / Product:

VMware vCenter Server

Required Action:

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Due Date: 12/11/2024(OVERDUE)
Added to KEV:

11/20/2024

Notes:

https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24968 ; https://nvd.nist.gov/vuln/detail/CVE-2024-38813

Vulnerability Summary

CVSS v3 Score

7.5HIGH

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS Score (Exploitation Probability)

29.53%LOW Exploitation Risk
97th percentile

This vulnerability has a 29.53% probability of being exploited in the next 30 days, ranking higher than 97% of all scored CVEs.

CWE Classification

Related Vulnerabilities

Same Weakness Type(CWE-250, CWE-273)

CVE-2025-40602MEDIUM 6.6

A local privilege escalation vulnerability due to insufficient authorization in the SonicWall SMA1000 appliance management console (AMC).

12/18/2025
CVE-2025-34515CRITICAL 9.8

Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain an execution with unnecessary privileges vulnerability in sync_project.sh that allows an attacker to escalate privileges to root. Ilevia has declined to service this vulnerability, and recommends that customers not expose port 8080 to the internet.

10/16/2025
CVE-2025-61958HIGH 8.7

A vulnerability exists in the iHealth command that may allow an authenticated attacker with at least a resource administrator role to bypass tmsh restrictions and gain access to a bash shell.  For BIG-IP systems running in Appliance mode, a successful exploit can allow the attacker to cross a security boundary.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

10/15/2025
CVE-2025-59481HIGH 8.7

A vulnerability exists in an undisclosed iControl REST and BIG-IP TMOS Shell (tmsh) command that may allow an authenticated attacker with at least resource administrator role to execute arbitrary system commands with higher privileges.  A successful exploit can allow the attacker to cross a security boundary.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

10/15/2025
CVE-2024-1222HIGH 8.6

This allows attackers to use a maliciously formed API request to gain access to an API authorization level with elevated privileges. This applies to a small subset of PaperCut NG/MF API calls.

3/14/2024

Similar SeverityHIGH