Lucene search

K
zdiSergey Gerasimov of SolidlabZDI-21-1106
HistorySep 22, 2021 - 12:00 a.m.

VMware vCenter Server Appliance Service Lifecycle Manager Incorrect Permission Assignment Privilege Escalation Vulnerability

2021-09-2200:00:00
Sergey Gerasimov of Solidlab
www.zerodayinitiative.com
20

0.0004 Low

EPSS

Percentile

16.1%

This vulnerability allows local attackers to escalate privileges on affected installations of VMware vCenter Server Appliance. An attacker must first obtain the ability to execute low-privileged code on the target guest system in order to exploit this vulnerability. The specific flaw exists within the Service Lifecycle Manager. The issue results from incorrect permissions set on a shell script. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of root.