---
# source: blog-content: posts/en/vmware-security-advisory-vmsa-2024-0012.md
# route:  /en/insights/vmware-security-advisory-vmsa-2024-0012/
title: VMware Security Advisory
date: 2024-06-19
author: daniel-stadelmann
locale: en
summary: VMware has disclosed a new vulnerability, covered by VMware Security Advisory 2024-0012. The issues are rated 7.8 to 9.8 on the CVSS scale.
capabilities: [security]
vendors: [vmware]
hero: /blog-assets/vmware-security-advisory-vmsa-2024-0012/hero.webp
migrated: 2026-08-24
translationReviewed: false
draft: false
---

VMware has disclosed a new vulnerability. It is covered by VMware Security Advisory 2024-0012 and the issues are rated 7.8 to 9.8 on the CVSS scale. The most severe one (CVSS 9.8) should be closed with the available update as soon as possible. Customers with Skyline active should already have been notified of the critical finding.

## VMSA-2024-0012

The published vulnerabilities ([CVE-2024-37079](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-37079), [CVE-2024-37080](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-37080), [CVE-2024-37081](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-37081)) let an attacker who is logged in locally on the vCenter appliance obtain root rights. Only vCenter is affected. Further detail and the fixed version are at [VMware](https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24453).

VMware reports no known attacks so far. With the vulnerabilities now published that can change within hours. Both soulTec and VMware recommend patching the affected systems immediately. If you need a hand, [we are here for you](https://soultec.ch/contact-us/).
