Threat Advisory

VMware Addresses Critical Vulnerabilities in ESXi, Workstation and Fusion

Threat: Vulnerability
Criticality: High
[subscribe_to_unlock_form]

Summary:

A series of critical security vulnerabilities have been discovered in VMware's ESXi, Workstation, and Fusion products, marked as CVE-2024-22252, CVE-2024-22253, CVE-2024-22254, and CVE-2024-22255. These vulnerabilities pose significant risks, with two critical flaws, CVE-2024-22252 and CVE-2024-22253, allowing for potential code execution due to use-after-free bugs in the XHCI USB controller. Exploitation of these flaws could lead to unauthorized code execution within the VMX process, compromising the integrity and security of virtual machines. Additionally, CVE-2024-22254 presents an out-of-bounds write vulnerability in ESXi, enabling a malicious actor with privileges within the VMX process to escape the sandbox. Furthermore, CVE-2024-22255 exposes an information disclosure vulnerability in the UHCI USB controller, potentially facilitating memory leakage from the vmx process.[/subscribe_to_unlock_form]

Summary:

A series of critical security vulnerabilities have been discovered in VMware's ESXi, Workstation, and Fusion products, marked as CVE-2024-22252, CVE-2024-22253, CVE-2024-22254, and CVE-2024-22255. These vulnerabilities pose significant risks, with two critical flaws, CVE-2024-22252 and CVE-2024-22253, allowing for potential code execution due to use-after-free bugs in the XHCI USB controller. Exploitation of these flaws could lead to unauthorized code execution within the VMX process, compromising the integrity and security of virtual machines. Additionally, CVE-2024-22254 presents an out-of-bounds write vulnerability in ESXi, enabling a malicious actor with privileges within the VMX process to escape the sandbox. Furthermore, CVE-2024-22255 exposes an information disclosure vulnerability in the UHCI USB controller, potentially facilitating memory leakage from the vmx process.[emaillocker id="1283"]

Recommendations:

  • We strongly recommend you update Vmware ESXi to version ESXi80U2sb-23305545, Workstation to version 17.5.1 and Fusion to version 13.5.1.

References:

The following reports contain further technical details:

https://thehackernews.com/2024/03/vmware-issues-security-patches-for-esxi.html

[/emaillocker]
crossmenu