Time-of-check Time-of-use (TOCTOU) Race Condition in VMware ESXi - CVE-2021-22043
Published: February 15, 2022
Vulnerability identifier: #VU60618
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-22043
CWE-ID: CWE-367
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to a Time-of-check Time-of-use vulnerability when handling temporary files. A local user with access to settingsd can escalate privileges on the system.
Affected software
VMware ESXi
Dell Enterprise Hybrid Cloud
Cloud Foundation
Dell Enterprise Hybrid Cloud
Cloud Foundation
How to mitigate CVE-2021-22043
Install updates from vendor's website.
VMware ESXi - addressed in versions ESXi70U1e-19324898, ESXi70U2e-19290878, ESXi70U3c-19193900
Dell Enterprise Hybrid Cloud - update to 4.1.2
Cloud Foundation - update to 4.4
Dell Enterprise Hybrid Cloud - update to 4.1.2
Cloud Foundation - update to 4.4