Use-after-free in VMware ESXi - CVE-2024-22252

 

Use-after-free in VMware ESXi - CVE-2024-22252

Published: March 5, 2024 / Updated: September 4, 2024


Vulnerability identifier: #VU87130
CSH Severity: High
CVSS v4: 8.5 [CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-22252
CWE-ID: CWE-416
Exploitation vector: Adjecent network
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to compromise vulnerable system.

The vulnerability exists due to a use-after-free error in the XHCI USB controller. A remote attacker with administrative access to the guest OS can trigger a use-after-free error and execute arbitrary code on the host OS.

On ESXi, the exploitation is contained within the VMX sandbox whereas, on Workstation and Fusion, this may lead to code execution on the machine where Workstation or Fusion is installed.


Affected software

VMware ESXi
VMware Fusion
VMware Workstation
PowerFlex Appliance
PowerFlex rack
Dell custom VMware ESXi

How to mitigate CVE-2024-22252

Install updates from vendor's website.

VMware ESXi - addressed in versions ESXi80U1d-23299997, ESXi80U2sb-23305545, ESXi70U3p-23307199
VMware Fusion - update to 13.5.1
VMware Workstation - update to 17.5.1
PowerFlex Appliance - update to IC-46.380.01
PowerFlex rack - update to 3.6.6.0
Dell custom VMware ESXi - addressed in versions 7.0U3-A20, 8.0U2-A06

External References

Related Security Bulletins