CVE-2024-22274
The vCenter Server contains an authenticated remote code execution vulnerability. A malicious actor with administrative privileges on the vCenter appliance shell may exploit this issue to run arbitrary commands on the underlying operating system.
- Affected products
- Vmware Vcenter, Vmware Vcenter Server
- Vmware Cloud Foundation
- < 5.1.1
- Vmware Vcenter Server
- = 7.0, 8.0
- CVSS 3.1
- 7.2 HIGH
- EPSS
- 2.5% (83th percentile)
- Weakness
- CWE-94
- NVD status
- Analyzed
- Published
- 2024-05-21
CVE-2024-22274 at NVD
3 known exploits for CVE-2024-22274
Proof-of-concept code and exploit modules indexed by Sploitus