CVE-2024-37081

HIGH

vCenter Sudo Privilege Escalation

Title source: metasploit
STIX 2.1

Exploitation Summary

EIP tracks 4 public exploits for CVE-2024-37081. PoCs published by Mr-r00t11, mbadanoiu, CERTologists, including Metasploit module exploits/linux/local/vcenter_sudo_lpe.

AI-analyzed exploit summary This repository contains a functional Python-based PoC for CVE-2024-37081, which exploits a misconfiguration in VMware vCenter's sudoers file to execute arbitrary commands with root privileges via environment variable manipulation.

Description

The vCenter Server contains multiple local privilege escalation vulnerabilities due to misconfiguration of sudo. An authenticated local user with non-administrative privileges may exploit these issues to elevate privileges to root on vCenter Server Appliance.

Exploits (4)

nomisec WORKING POC 58 stars
by Mr-r00t11 · poc
https://github.com/Mr-r00t11/CVE-2024-37081

This repository contains a functional Python-based PoC for CVE-2024-37081, which exploits a misconfiguration in VMware vCenter's sudoers file to execute arbitrary commands with root privileges via environment variable manipulation.

Classification
Working Poc 95%
Attack Type
Lpe
Complexity
Moderate
Reliability
Reliable
Target: VMware vCenter
Auth required
Prerequisites: Access to a vulnerable VMware vCenter system · Membership in affected groups (operator, admin, etc.) · Python 3.x
devstral-2 · analyzed Feb 18, 2026 Full analysis →
nomisec SUSPICIOUS 10 stars
by mbadanoiu · poc
https://github.com/mbadanoiu/CVE-2024-37081

The repository claims to detail a local privilege escalation vulnerability in VMware vCenter Server due to sudo misconfiguration but provides no actual exploit code. Instead, it redirects users to an external PDF for details, which is a common tactic in suspicious repositories.

Classification
Suspicious 90%
Attack Type
Lpe
Complexity
Theoretical
Reliability
Theoretical
Target: VMware vCenter Server
Auth required
Prerequisites: local access to the vCenter Server Appliance · authenticated non-administrative user privileges
devstral-2 · analyzed Feb 18, 2026 Full analysis →
nomisec SUSPICIOUS
by CERTologists · poc
https://github.com/CERTologists/Modified-CVE-2024-37081-POC

The repository contains only a vague README with no technical details or exploit code, claiming a 'modified' PoC for CVE-2024-37081 without providing any substance. It appears to be a social engineering lure.

Classification
Suspicious 90%
Attack Type
Other
Complexity
Theoretical
Reliability
Theoretical
Target: VMware vCenter
No auth needed
devstral-2 · analyzed Feb 18, 2026 Full analysis →
metasploit WORKING POC GREAT
by h00die, Matei, Badanoiu · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/local/vcenter_sudo_lpe.rb

This Metasploit module exploits a sudo misconfiguration in VMware vCenter Server to achieve local privilege escalation (LPE) by leveraging environment variable manipulation (PYTHONPATH, VMWARE_PYTHON_PATH, or VMWARE_PYTHON_BIN) to execute arbitrary payloads as root.

Classification
Working Poc 100%
Attack Type
Lpe
Complexity
Moderate
Reliability
Reliable
Target: VMware vCenter Server < 7.0.3 update R and < 8.0.2 update D
Auth required
Prerequisites: Authenticated local access to vCenter Server Appliance · User must be in 'infraprofile', 'vpxd', 'sts', 'pod', 'operator', or 'admin' groups
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Scores

CVSS v3 7.8
EPSS 0.0499
EPSS Percentile 91.1%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-556
Status published
Products (3)
vmware/cloud_foundation 4.0 - 5.2
vmware/vcenter_server 8.0 (14 CPE variants)
vmware/vcenter_server 7.0 (31 CPE variants)
Published Jun 18, 2024
Tracked Since Feb 18, 2026