Malware & Threats

VMware Patches High-Severity Vulnerabilities in Aria Operations

The company warns that malicious hackers can craft exploits to elevate privileges or launch cross-site scripting attacks.

The company warns that malicious hackers can craft exploits to elevate privileges or launch cross-site scripting attacks.

Virtualization software vendor VMware on Tuesday released a high-severity bulletin with patches for at least five security defects in its Aria Operations product.

The company documented five distinct vulnerabilities in the cloud IT operations platform and warned that malicious hackers can craft exploits to elevate privileges or launch cross-site scripting attacks.

Here are the details from VMware’s VMSA-2024-0022 bulletin

  • CVE-2024-38830 – Local privilege escalation vulnerability (CVSS 7.8). Exploitable by actors with local administrative privileges to gain root access on the appliance.
  • CVE-2024-38831 – Local privilege escalation vulnerability (CVSS 7.8). Enables malicious commands via properties file modifications, allowing privilege escalation to root.
  • CVE-2024-38832 – Stored cross-site scripting vulnerability (CVSS 7.1). Allows script injection by users with editing access to views.
  • CVE-2024-38833 – Stored cross-site scripting vulnerability (CVSS 6.8). Permits malicious script injection through email templates.
  • CVE-2024-38834 – Stored cross-site scripting vulnerability (CVSS 6.5). Targets cloud provider editing functionality for script injection.

The company said the vulnerabilities affect VMware Aria Operations (version 8.x), and VMware Cloud Foundation (versions 4.x and 5.x utilizing Aria Operations).

Corporate users are urged to apply the available patches urgently with VMware noting that there are no available workarounds.

VMware virtualization technology products have been a major target for advanced hacking groups.  The CISA Known Exploited Vulnerabilities (KEV) catalog includes multiple entries for VMware defects, including at least one for VMware Aria Operations.

Related: Hard-to-Fix VMware vCenter Server Flaw Being Exploited

Advertisement. Scroll to continue reading.

Related: VMware Struggles to Fix Flaw Exploited at Chinese Hacking Contest

Related: VMware Patches High-Severity SQL Injection Flaw in HCX Platform

Related: VMware Patches RCE Flaw Found in Chinese Hacking Contest

Related Content

Vulnerabilities

The flaws could allow attackers with administrative access to a virtual machine to execute code on the host system.

Vulnerabilities

The flaws can be exploited for remote code execution, authentication bypass, and device takeover.

Vulnerabilities

Tracked as CVE-2026–59310, the directory traversal bug allows remote attackers to execute arbitrary code.

Vulnerabilities

A total of five vulnerabilities have been patched in VMware ESXi, vCenter, Workstation, and Fusion.

Vulnerabilities

The flaws can be exploited for authentication bypass, remote code execution, privilege escalation, and directory traversal.

Vulnerabilities

The patch was announced as Broadcom is attending the Pwn2Own hacking competition in Berlin this week.

Vulnerabilities

The recently patched CVE-2026-22719 can be exploited by an unauthenticated attacker for remote code execution. 

Vulnerabilities

Broadcom has patched several vulnerabilities in VMware Aria Operations, including high-severity flaws.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version