logo

VMware fixes critical RCE, make-me-root bugs in vCenter - for the second time

ID: 43423331-0144-53e0-862a-337b7913930c

STIX ID: report--43423331-0144-53e0-862a-337b7913930c

Feed Name: The Register (Security)

Threat Score
78/100

Date Published: 2024-10-22

Date Updated: 2026-04-26

Author: Jessica Lyons

...
...

VMware issued a second security update to fully fix two serious vCenter vulnerabilities after the initial September patches failed to completely resolve them. CVE-2024-38812 is a critical, unauthenticated remote code execution flaw (CVSS 9.8) affecting multiple vCenter/vSphere/VMware Cloud Foundation versions, and CVE-2024-38813 is a privilege-escalation bug (CVSS 7.5) that can lead to root. Broadcom warns there are no workarounds, recommends immediate patching, and currently reports no known exploitation in the wild.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.