CPE
high
advisory
VMware vCenter Server Backup API Flag Injection Vulnerability (CVE-2024-22274)
2 TTPs 1 CVEA newly released PoC exploit for CVE-2024-22274 enables authenticated attackers to perform flag injection within VMware vCenter Server backup API components, resulting in remote code execution as root.
VMware Cloud Foundation +1
vmware
rce
vulnerability
cve-2024-22274
2t
1c
high
advisory
Potential CVE-2025-41244 vmtoolsd Local Privilege Escalation Attempt
1 rule 3 TTPs 1 CVEAttackers can exploit CVE-2025-41244, a local privilege escalation vulnerability in VMware Tools' `vmtoolsd` service and its `get-versions.sh` script on Linux, by manipulating the `PATH` environment variable to execute malicious binaries with elevated privileges when the service attempts to retrieve version information, potentially leading to a root shell.
VMware Tools +1
privilege-escalation
vmware
linux
vulnerability
1r
3t
1c