QID 731178

Date Published: 2024-03-11

QID 731178: VMware Aria Operations Local Privilege Escalation Vulnerability (VMSA-2024-0004)

A local privilege escalation vulnerability affecting Aria Operations was responsibly reported to VMware.

Affected Versions:
VMware Aria Operations versions 8.x prior to version 8.16 Build 23251571

QID Detection Logic
This QID sends the GET request to ui/login.action and checks for vulnerable version.

A malicious actor with administrative access to the local system can escalate privileges to root.

  • CVSS V3 rated as High - 6.7 severity.
  • CVSS V2 rated as High - 6.5 severity.
  • Solution
    Customers are advised to upgrade to VMware Aria Operations version. For more information please refer to VMSA-2024-0004

    CVEs related to QID 731178

    Software Advisories
    Advisory ID Software Component Link
    VMSA-2024-0004 URL Logo www.vmware.com/security/advisories/VMSA-2024-0004.html