Skip to content

Latest commit

 

History

History
17 lines (10 loc) · 818 Bytes

README.md

File metadata and controls

17 lines (10 loc) · 818 Bytes

CVE-2024-22275: Partial File Read in VMware vCenter Server

The vCenter Server contains a partial file read vulnerability. A malicious actor with administrative privileges on the vCenter appliance shell may exploit this issue to partially read arbitrary files containing sensitive data.

Vendor Disclosure:

The vendor's disclosure for this vulnerability can be found here.

Requirements:

This vulnerability requires:

  • Valid credentials for a user that can execute the "com.vmware.rvc" command

Proof Of Concept:

More details and the exploitation process can be found in this PDF.