Buffer overflow in VMware ESXi - CVE-2022-31696

 

Buffer overflow in VMware ESXi - CVE-2022-31696

Published: December 9, 2022 / Updated: December 26, 2022


Vulnerability identifier: #VU70077
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-31696
CWE-ID: CWE-119
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to a boundary error in the way network socket are handled. A local privileged user can trigger memory corruption and execute arbitrary code with elevated privileges.


Affected software

VMware ESXi
IBM Cloud Pak System
PowerFlex Appliance
PowerFlex rack
VxFlex ESXi

How to mitigate CVE-2022-31696

Install updates from vendor's website.

VMware ESXi - addressed in versions ESXi650-202210101-SG, ESXi670-202210101-SG, ESXi70U3si-20841705
IBM Cloud Pak System - update to 2.3.3.6
PowerFlex Appliance - update to IC 38.363.02
PowerFlex rack - update to 3.6.3.2
VxFlex ESXi - update to 7.0U3i

External References

Related Security Bulletins