target entity

vCenter Server

9 source-linked records in the current knowledge graph.

high

CVE-2024-38813: VMware vCenter Server Privilege Escalation Vulnerability

VMware vCenter contains an improper check for dropped privileges vulnerability. This vulnerability could allow an attacker with network access to the vCenter Server to escalate privileges to root by sending a specially crafted packet. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2024-38813EPSS 16.7%VMwarevCenter Server
CISA KEV ↗ · unattributed attribution
high

CVE-2024-38812: VMware vCenter Server Heap-Based Buffer Overflow Vulnerability

VMware vCenter Server contains a heap-based buffer overflow vulnerability in the implementation of the DCERPC protocol. This vulnerability could allow an attacker with network access to the vCenter Server to execute remote code by sending a specially crafted packet. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2024-38812EPSS 54.1%VMwarevCenter Server
CISA KEV ↗ · unattributed attribution
high

CVE-2023-34048: VMware vCenter Server Out-of-Bounds Write Vulnerability

VMware vCenter Server contains an out-of-bounds write vulnerability in the implementation of the DCERPC protocol that allows an attacker to conduct remote code execution. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2023-34048EPSS 99.4%VMwarevCenter Server
CISA KEV ↗ · unattributed attribution
high

CVE-2021-22005: VMware vCenter Server File Upload Vulnerability

VMware vCenter Server contains a file upload vulnerability in the Analytics service that allows a user with network access to port 443 to execute code. Required action: Apply updates per vendor instructions.

CVE-2021-22005EPSS 100.0%VMwarevCenter Server
CISA KEV ↗ · unattributed attribution
high

CVE-2020-3952: VMware vCenter Server Information Disclosure Vulnerability

VMware vCenter Server contains an information disclosure vulnerability in the VMware Directory Service (vmdir) when the Platform Services Controller (PSC) does not correctly implement access controls. Successful exploitation allows an attacker with network access to port 389 to extract sensitive information. Required action: Apply updates per vendor instructions.

CVE-2020-3952EPSS 90.4%VMwarevCenter Server
CISA KEV ↗ · unattributed attribution
high

CVE-2021-21972: VMware vCenter Server Remote Code Execution Vulnerability

VMware vCenter Server vSphere Client contains a remote code execution vulnerability in a vCenter Server plugin which allows an attacker with network access to port 443 to execute commands with unrestricted privileges on the underlying operating system. Required action: Apply updates per vendor instructions.

CVE-2021-21972EPSS 99.6%VMwarevCenter Server
CISA KEV ↗ · unattributed attribution