Skip to main content

VMware Releases Critical Security Updates for Multiple Products

The vulnerabilities could allow an attacker to execute arbitrary code, escape the sandboxed environment, and read protected memory in VMware hypervisors

Report a cyber attack: call 0300 303 5222 or email [email protected]

Summary

The vulnerabilities could allow an attacker to execute arbitrary code, escape the sandboxed environment, and read protected memory in VMware hypervisors


Threat details

Introduction

VMware has released multiple security updates to address multiple vulnerabilities in VMware ESXi, VMware Workstation Pro/Player, VMware Fusion Pro/Fusion, and VMware Cloud Foundation. All platforms are affected by the following vulnerabilities:

  • CVE-2024-22252 - a use-after-free vulnerability in the XHCI USB controller with a CVSSv3 score of 9.3, which if exploited could allow a local attacker with administrator privileges in the virtualised machine to execute arbitrary code on the host machine.
  • CVE-2024-22253 - a use-after-free vulnerability in the UHCI USB controller with a CVSSv3 score of 9.3, which if exploited could allow a local attacker with administrator privileges in the virtualised machine to execute arbitrary code on the host machine.
  • CVE-2024-22255 - an information disclosure vulnerability in the UHCI USB controller with a CVSSv3 score of 7.1, which if exploited could allow a local attacker to leak memory from the hypervisor process.

VMware ESXi and the ESXi component of VMware Cloud Foundation are also vulnerable to CVE-2024-22254, an out-of-bounds write vulnerability with a CVSSv3 score of 7.9. A local attacker could exploit this vulnerability to escape the sandbox onto the host machine.


Remediation advice

Affected organisations are encouraged to review VMware Security Advisory VMSA-2024-0006 and apply any relevant updates.



CVE Vulnerabilities

Last edited: 6 March 2024 1:48 pm