Buffer overflow in VMware ESXi - CVE-2022-31696
Published: December 9, 2022 / Updated: December 26, 2022
Vulnerability identifier: #VU70077
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-31696
CWE-ID: CWE-119
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to a boundary error in the way network socket are handled. A local privileged user can trigger memory corruption and execute arbitrary code with elevated privileges.
Affected software
VMware ESXi
IBM Cloud Pak System
PowerFlex Appliance
PowerFlex rack
VxFlex ESXi
IBM Cloud Pak System
PowerFlex Appliance
PowerFlex rack
VxFlex ESXi
How to mitigate CVE-2022-31696
Install updates from vendor's website.
VMware ESXi - addressed in versions ESXi650-202210101-SG, ESXi670-202210101-SG, ESXi70U3si-20841705
IBM Cloud Pak System - update to 2.3.3.6
PowerFlex Appliance - update to IC 38.363.02
PowerFlex rack - update to 3.6.3.2
VxFlex ESXi - update to 7.0U3i
IBM Cloud Pak System - update to 2.3.3.6
PowerFlex Appliance - update to IC 38.363.02
PowerFlex rack - update to 3.6.3.2
VxFlex ESXi - update to 7.0U3i