Heap-based buffer overflow in VMware ESXi - CVE-2021-22045
Published: January 4, 2022 / Updated: February 15, 2022
Vulnerability identifier: #VU59182
CSH Severity: High
CVSS v4: 7.7 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-22045
CWE-ID: CWE-122
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to a boundary error. A remote attacker with access to the guest OS with D-ROM device emulation can trigger heap-based buffer overflow and execute arbitrary code on the hypervisor.
Affected software
VMware ESXi
Dell Enterprise Hybrid Cloud
VMware Workstation
VMware Fusion
Dell EMC VxRail Appliance
Dell Enterprise Hybrid Cloud
VMware Workstation
VMware Fusion
Dell EMC VxRail Appliance
How to mitigate CVE-2021-22045
Install updates from vendor's website.
VMware ESXi - addressed in versions ESXi650-202110101-SG, ESXi670-202111101-SG, ESXi70U3c-19193900
Dell Enterprise Hybrid Cloud - update to 4.1.2
VMware Workstation - update to 16.2.0
Dell EMC VxRail Appliance - update to 4.5.471
VMware Fusion - update to 12.2.0
Dell Enterprise Hybrid Cloud - update to 4.1.2
VMware Workstation - update to 16.2.0
Dell EMC VxRail Appliance - update to 4.5.471
VMware Fusion - update to 12.2.0