Out-of-bounds write in VMware ESXi - CVE-2022-31705
Published: December 13, 2022 / Updated: January 9, 2023
VMware ESXi
Detailed vulnerability description
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to a boundary error within the USB 2.0 controller (EHCI). A local privileged user on the guest OS can trigger an out-of-bounds write and execute arbitrary code as the virtual machine's VMX process running on the host.
How to mitigate CVE-2022-31705
Install updates from vendor's website.
Note, on ESXi the exploitation is contained within the VMX sandbox.