Out-of-bounds write in VMware ESXi - CVE-2022-31705

 

Out-of-bounds write in VMware ESXi - CVE-2022-31705

Published: December 13, 2022 / Updated: January 9, 2023


Vulnerability identifier: #VU70156
CSH Severity: Medium
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-31705
CWE-ID: CWE-787
Exploitation vector: Remote access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to a boundary error within the USB 2.0 controller (EHCI). A local privileged user on the guest OS can trigger an out-of-bounds write and execute arbitrary code as the virtual machine's VMX process running on the host.


Affected software

VMware ESXi
VMware Fusion
VMware Workstation
PowerFlex Appliance
PowerFlex rack
VxFlex ESXi

How to mitigate CVE-2022-31705

Install updates from vendor's website.

Note, on ESXi the exploitation is contained within the VMX sandbox.


VMware ESXi - addressed in versions ESXi80a-20842819, ESXi70U3si-20841705
VMware Fusion - update to 12.2.5
VMware Workstation - update to 16.2.5
PowerFlex Appliance - update to IC 38.363.02
PowerFlex rack - update to 3.6.3.2
VxFlex ESXi - update to 7.0U3i

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins