CVE-2024-37081: VMware Cloud Foundation

High severity, CVSS 7.8. EPSS: 5% chance of exploitation in the next 30 days.

The vCenter Server contains multiple local privilege escalation vulnerabilities due to misconfiguration of sudo. An authenticated local user with non-administrative privileges may exploit these issues to elevate privileges to root on vCenter Server Appliance.

Affected products

  • VMware Cloud Foundation: from 4.0, before 5.2 (fixed in 5.2)
  • VMware vCenter Server: version 8.0 only; version 7.0 only

Published 2024-06-18. Last modified 2026-06-17.