{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3avmwarevcenter_server7.0update2c/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:vmware:vcenter_server:7.0:*:*:*:*:*:*:*","cpe:2.3:a:vmware:vcenter_server:8.0:*:*:*:*:*:*:*","cpe:2.3:a:vmware:cloud_foundation:*:*:*:*:*:*:*:*","cpe:2.3:a:vmware:vcenter_server:7.0:-:*:*:*:*:*:*","cpe:2.3:a:vmware:vcenter_server:7.0:a:*:*:*:*:*:*","cpe:2.3:a:vmware:vcenter_server:7.0:b:*:*:*:*:*:*","cpe:2.3:a:vmware:vcenter_server:7.0:c:*:*:*:*:*:*","cpe:2.3:a:vmware:vcenter_server:7.0:d:*:*:*:*:*:*","cpe:2.3:a:vmware:vcenter_server:7.0:update1:*:*:*:*:*:*","cpe:2.3:a:vmware:vcenter_server:7.0:update1a:*:*:*:*:*:*","cpe:2.3:a:vmware:vcenter_server:7.0:update1c:*:*:*:*:*:*","cpe:2.3:a:vmware:vcenter_server:7.0:update1d:*:*:*:*:*:*","cpe:2.3:a:vmware:vcenter_server:7.0:update2:*:*:*:*:*:*","cpe:2.3:a:vmware:vcenter_server:7.0:update2a:*:*:*:*:*:*","cpe:2.3:a:vmware:vcenter_server:7.0:update2b:*:*:*:*:*:*","cpe:2.3:a:vmware:vcenter_server:7.0:update2c:*:*:*:*:*:*","cpe:2.3:a:vmware:vcenter_server:7.0:update2d:*:*:*:*:*:*","cpe:2.3:a:vmware:vcenter_server:7.0:update3:*:*:*:*:*:*","cpe:2.3:a:vmware:vcenter_server:7.0:update3a:*:*:*:*:*:*","cpe:2.3:a:vmware:vcenter_server:7.0:update3c:*:*:*:*:*:*","cpe:2.3:a:vmware:vcenter_server:7.0:update3d:*:*:*:*:*:*","cpe:2.3:a:vmware:vcenter_server:7.0:update3e:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.2,"id":"CVE-2024-22274"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["VMware Cloud Foundation (\u003c 5.1.1)","vCenter Server (7.0, 8.0)"],"_cs_severities":["high"],"_cs_tags":["vmware","rce","vulnerability","cve-2024-22274"],"_cs_type":"advisory","_cs_vendors":["VMware"],"content_html":"\u003cp\u003eCVE-2024-22274 is a high-severity vulnerability affecting VMware vCenter Server and VMware Cloud Foundation. The vulnerability stems from improper handling of inputs within the backup API components, specifically 'com.vmware.appliance.recovery.backup.job.create' and 'com.vmware.appliance.recovery.backup.validate'. An attacker who has already obtained valid administrative credentials can leverage this flaw to perform flag injection, which facilitates arbitrary command execution with root privileges on the underlying appliance.\u003c/p\u003e\n\u003cp\u003eThe public availability of a functional PoC exploit as of August 2026 significantly increases the risk to unpatched infrastructure. Because vCenter Server is a critical component for managing virtualized environments, successful exploitation grants an attacker full control over the virtual infrastructure and the ability to exfiltrate sensitive data. Organizations running affected versions of VMware vCenter Server or VMware Cloud Foundation should prioritize patching to the versions that remediate these specific backup API security flaws.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker gains valid administrative credentials for the target VMware vCenter Server instance through prior compromise or credential theft.\u003c/li\u003e\n\u003cli\u003eAttacker establishes an authenticated SSH session to the vCenter Server appliance.\u003c/li\u003e\n\u003cli\u003eAttacker clones the public PoC repository and prepares a payload file (\u003ccode\u003epayload.txt\u003c/code\u003e) containing the malicious commands to be executed.\u003c/li\u003e\n\u003cli\u003eAttacker utilizes the PoC Python script to interface with the vulnerable backup API components (\u003ccode\u003ecom.vmware.appliance.recovery.backup.job.create\u003c/code\u003e or \u003ccode\u003ecom.vmware.appliance.recovery.backup.validate\u003c/code\u003e).\u003c/li\u003e\n\u003cli\u003eThe API component fails to properly sanitize the input, allowing the attacker to inject flags that modify the command execution context.\u003c/li\u003e\n\u003cli\u003eThe injected commands execute on the appliance operating system with root (UID 0) privileges.\u003c/li\u003e\n\u003cli\u003eAttacker achieves the final objective of full system control, allowing for lateral movement, data exfiltration, or further persistence within the virtualized environment.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2024-22274 allows an authenticated attacker to execute arbitrary commands as root. This provides full control over the vCenter Server, enabling attackers to compromise the entire virtualized infrastructure, manipulate virtual machines, exfiltrate sensitive enterprise data, and maintain persistent access within the management network.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize patching VMware vCenter Server and VMware Cloud Foundation to versions identified by the vendor as no longer vulnerable. Audit administrative access to vCenter Server instances and implement multi-factor authentication (MFA) to prevent unauthorized use of credentials. Monitor SSH logs for connections from unrecognized or suspicious source IPs that interact with the vCenter backup API scripts.\u003c/p\u003e\n","date_modified":"2026-08-30T04:10:59Z","date_published":"2026-08-30T04:10:59Z","id":"https://feed.craftedsignal.io/briefs/2026-08-cve-2024-22274/","summary":"A newly released PoC exploit for CVE-2024-22274 enables authenticated attackers to perform flag injection within VMware vCenter Server backup API components, resulting in remote code execution as root.","title":"VMware vCenter Server Backup API Flag Injection Vulnerability (CVE-2024-22274)","url":"https://feed.craftedsignal.io/briefs/2026-08-cve-2024-22274/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:vmware:vcenter_server:7.0:update2c:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}