CVE-2024-38830

Severity CVSS v4.0:
Pending analysis
Type:
CWE-269 Improper Privilege Management
Publication date:
26/11/2024
Last modified:
14/05/2025

Description

VMware Aria Operations contains a local privilege escalation vulnerability. A malicious actor with local administrative privileges may trigger this vulnerability to escalate privileges to root user on the appliance running VMware Aria Operations.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:vmware:aria_operations:*:*:*:*:*:*:*:* 8.0 (including) 8.18.2 (excluding)
cpe:2.3:a:vmware:cloud_foundation:*:*:*:*:*:*:*:* 4.0 (including) 5.2 (including)