CVE-2024-38830

HIGH

VMware Aria Operations 8.0-8.18.1 - Local Privilege Escalation to Root

Title source: llm
STIX 2.1

Description

VMware Aria Operations contains a local privilege escalation vulnerability. A malicious actor with local administrative privileges may trigger this vulnerability to escalate privileges to root user on the appliance running VMware Aria Operations.

Scores

CVSS v3 7.8
EPSS 0.0008
EPSS Percentile 22.7%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-269
Status published
Products (2)
vmware/aria_operations 8.0 - 8.18.2
vmware/cloud_foundation 4.0 - 5.2
Published Nov 26, 2024
Tracked Since Feb 18, 2026