CVE-2024-22274

HIGH

vCenter Server - RCE

Title source: llm

Description

The vCenter Server contains an authenticated remote code execution vulnerability. A malicious actor with administrative privileges on the vCenter appliance shell may exploit this issue to run arbitrary commands on the underlying operating system.

Exploits (4)

nomisec WORKING POC 44 stars
by l0n3m4n · poc
https://github.com/l0n3m4n/CVE-2024-22274-RCE
nomisec SUSPICIOUS 38 stars
by mbadanoiu · poc
https://github.com/mbadanoiu/CVE-2024-22274
nomisec WORKING POC
by ninhpn1337 · poc
https://github.com/ninhpn1337/CVE-2024-22274
nomisec WORKING POC
by Mustafa1986 · poc
https://github.com/Mustafa1986/CVE-2024-22274-RCE

Scores

CVSS v3 7.2
EPSS 0.6516
EPSS Percentile 98.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Classification

CWE
CWE-94
Status published

Affected Products (43)

vmware/cloud_foundation < 5.1.1
vmware/vcenter_server
vmware/vcenter_server
vmware/vcenter_server
vmware/vcenter_server
vmware/vcenter_server
vmware/vcenter_server
vmware/vcenter_server
vmware/vcenter_server
vmware/vcenter_server
vmware/vcenter_server
vmware/vcenter_server
vmware/vcenter_server
vmware/vcenter_server
vmware/vcenter_server
... and 28 more

Timeline

Published May 21, 2024
Tracked Since Feb 18, 2026