Out-of-bounds write in VMware ESXi - CVE-2022-31705
Published: December 13, 2022 / Updated: January 9, 2023
Vulnerability details
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to a boundary error within the USB 2.0 controller (EHCI). A local privileged user on the guest OS can trigger an out-of-bounds write and execute arbitrary code as the virtual machine's VMX process running on the host.
Affected software
VMware Fusion
VMware Workstation
PowerFlex Appliance
PowerFlex rack
VxFlex ESXi
How to mitigate CVE-2022-31705
Install updates from vendor's website.
Note, on ESXi the exploitation is contained within the VMX sandbox.
VMware Fusion - update to 12.2.5
VMware Workstation - update to 16.2.5
PowerFlex Appliance - update to IC 38.363.02
PowerFlex rack - update to 3.6.3.2
VxFlex ESXi - update to 7.0U3i