CyberzSOC

Publication detail
← Back to advisories & guidance

2024-024: Vulnerabilities in VMware Products ↗ source

March 7, 2024 CERT-EU Advisory

Summary

The most serious bugs could allow a malicious actor with local admin privileges on a virtual machine to execute code as the virtual machine’s VMX process running on the host. It is recommended upgrading affected software as soon as possible. The vulnerabilities CVE-2024-22252 and CVE-2024-22253, both with a CVSS score of 9.3 Workstation/Fusion and of 8.4 for ESXi, are Use-after-free vulnerability in XHCI USB controller and in the UHCI USB controller. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine’s VMX process running on the host. On ESXi, the exploitation is contained within the VMX sandbox whereas, on Workstation and Fusion, this may lead to code execution on the machine where Workstation The vulnerability CVE-2024-22254, with a CVSS score of 7.9, is an out-of-bounds write vulnerability in ESXi.

News Coverage

No coverage found in monitored research blogs or news feeds.

CVEs Referenced in This Publication

CVECVSSAffected
CVE-2024-22252 9.3 Critical n/a VMware ESXi VMware ESXi, Workstation, and Fusion contain a use-after-free vulnerability in the XHCI USB controller. A malicious actor with local administrative p…
CVE-2024-22253 9.3 Critical n/a VMware ESXi VMware ESXi, Workstation, and Fusion contain a use-after-free vulnerability in the UHCI USB controller. A malicious actor with local administrative p…
CVE-2024-22254 7.9 High n/a VMware ESXi VMware ESXi contains an out-of-bounds write vulnerability. A malicious actor with privileges within the VMX process may trigger an out-of-bounds writ…
CVE-2024-22255 7.1 High n/a VMware ESXi VMware ESXi, Workstation, and Fusion contain an information disclosure vulnerability in the UHCI USB controller. A malicious actor with administrativ…

Extracted from the publication text. Each CVE links to its tracked detail page.

Vendors Named in This Publication

Each vendor links to its Known Exploited Vulnerabilities catalog page. Only vendors that appear in the KEV catalog are listed, either because the publication cites one of their KEV entries or because it names them directly.