Use-after-free in VMware ESXi - CVE-2024-22252
Published: March 5, 2024 / Updated: September 4, 2024
Vulnerability details
The vulnerability allows a remote user to compromise vulnerable system.
The vulnerability exists due to a use-after-free error in the XHCI USB controller. A remote attacker with administrative access to the guest OS can trigger a use-after-free error and execute arbitrary code on the host OS.
On ESXi, the exploitation is contained within the VMX sandbox whereas, on Workstation and Fusion, this may lead to code execution on the machine where Workstation or Fusion is installed.
Affected software
VMware Fusion
VMware Workstation
PowerFlex Appliance
PowerFlex rack
Dell custom VMware ESXi
How to mitigate CVE-2024-22252
VMware Fusion - update to 13.5.1
VMware Workstation - update to 17.5.1
PowerFlex Appliance - update to IC-46.380.01
PowerFlex rack - update to 3.6.6.0
Dell custom VMware ESXi - addressed in versions 7.0U3-A20, 8.0U2-A06
External References
Related Security Bulletins
- Multiple vulnerabilities in VMware ESXi
- Multiple vulnerabilities in VMware Workstation and Fusion
- Multiple vulnerabilities in Dell Custom VMware ESXi
- Multiple vulnerabilities in Dell PowerFlex Rack
- Multiple vulnerabilities in Dell PowerFlex Appliance
- Multiple vulnerabilities in Dell PowerFlex Appliance