VMware Releases Critical Security Updates for Multiple Products
The vulnerabilities could allow an attacker to execute arbitrary code, escape the sandboxed environment, and read protected memory in VMware hypervisors
Summary
The vulnerabilities could allow an attacker to execute arbitrary code, escape the sandboxed environment, and read protected memory in VMware hypervisors
Affected platforms
The following platforms are known to be affected:
Threat details
Introduction
VMware has released multiple security updates to address multiple vulnerabilities in VMware ESXi, VMware Workstation Pro/Player, VMware Fusion Pro/Fusion, and VMware Cloud Foundation. All platforms are affected by the following vulnerabilities:
- CVE-2024-22252 - a use-after-free vulnerability in the XHCI USB controller with a CVSSv3 score of 9.3, which if exploited could allow a local attacker with administrator privileges in the virtualised machine to execute arbitrary code on the host machine.
- CVE-2024-22253 - a use-after-free vulnerability in the UHCI USB controller with a CVSSv3 score of 9.3, which if exploited could allow a local attacker with administrator privileges in the virtualised machine to execute arbitrary code on the host machine.
- CVE-2024-22255 - an information disclosure vulnerability in the UHCI USB controller with a CVSSv3 score of 7.1, which if exploited could allow a local attacker to leak memory from the hypervisor process.
VMware ESXi and the ESXi component of VMware Cloud Foundation are also vulnerable to CVE-2024-22254, an out-of-bounds write vulnerability with a CVSSv3 score of 7.9. A local attacker could exploit this vulnerability to escape the sandbox onto the host machine.
Remediation advice
Affected organisations are encouraged to review VMware Security Advisory VMSA-2024-0006 and apply any relevant updates.
Definitive source of threat updates
CVE Vulnerabilities
Last edited: 6 March 2024 1:48 pm