NULL pointer dereference in VMware ESXi - CVE-2022-31681
Published: October 7, 2022
Vulnerability identifier: #VU67979
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-31681
CWE-ID: CWE-476
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to a NULL pointer dereference error. A local user with privileges within the VMX process only can perform a denial of service (DoS) attack against the host.
Affected software
VMware ESXi
IBM Cloud Pak System
Dell Enterprise Hybrid Cloud
VxFlex ESXi
IBM Cloud Pak System
Dell Enterprise Hybrid Cloud
VxFlex ESXi
How to mitigate CVE-2022-31681
Install updates from vendor's website.
VMware ESXi - addressed in versions ESXi650-202210101-SG, ESXi670-202210101-SG, ESXi70U3sf-20036586
IBM Cloud Pak System - update to 2.3.3.6
Dell Enterprise Hybrid Cloud - update to 4.1.2
VxFlex ESXi - update to 7.0U3i
IBM Cloud Pak System - update to 2.3.3.6
Dell Enterprise Hybrid Cloud - update to 4.1.2
VxFlex ESXi - update to 7.0U3i