Out-of-bounds write in VMware ESXi - CVE-2024-22254
Published: March 5, 2024 / Updated: September 4, 2024
Vulnerability identifier: #VU87132
CSH Severity: Low
CVSS v4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-22254
CWE-ID: CWE-787
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to a boundary error when processing untrusted input. A local user with privileges within the VMX process can trigger an out-of-bounds write and escape sandbox restrictions.
Affected software
VMware ESXi
PowerFlex Appliance
PowerProtect DP Series Appliance (IDPA)
PowerFlex rack
IBM Cloud Pak System
Dell custom VMware ESXi
PowerFlex Appliance
PowerProtect DP Series Appliance (IDPA)
PowerFlex rack
IBM Cloud Pak System
Dell custom VMware ESXi
How to mitigate CVE-2024-22254
Install updates from vendor's website.
VMware ESXi - addressed in versions ESXi80U1d-23299997, ESXi80U2sb-23305545, ESXi70U3p-23307199
PowerFlex Appliance - update to IC-46.380.01
IBM Cloud Pak System - update to 2.3.4.1
PowerProtect DP Series Appliance (IDPA) - update to 2.7.7
PowerFlex rack - update to 3.6.6.0
Dell custom VMware ESXi - addressed in versions 7.0U3-A20, 8.0U2-A06
PowerFlex Appliance - update to IC-46.380.01
IBM Cloud Pak System - update to 2.3.4.1
PowerProtect DP Series Appliance (IDPA) - update to 2.7.7
PowerFlex rack - update to 3.6.6.0
Dell custom VMware ESXi - addressed in versions 7.0U3-A20, 8.0U2-A06
External References
Related Security Bulletins
- Multiple vulnerabilities in VMware ESXi
- Multiple vulnerabilities in Dell Custom VMware ESXi
- Multiple vulnerabilities in Dell PowerFlex Rack
- Multiple vulnerabilities in Dell PowerFlex Appliance
- Multiple vulnerabilities in Dell PowerFlex Appliance
- Multiple vulnerabilities in IBM Cloud Pak System
- Multiple vulnerabilities in Dell PowerProtect DP Series Appliance (IDPA)