Out-of-bounds write in VMware ESXi - CVE-2024-22254

 

Out-of-bounds write in VMware ESXi - CVE-2024-22254

Published: March 5, 2024 / Updated: September 4, 2024


Vulnerability identifier: #VU87132
CSH Severity: Low
CVSS v4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-22254
CWE-ID: CWE-787
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to a boundary error when processing untrusted input. A local user with privileges within the VMX process can trigger an out-of-bounds write and escape sandbox restrictions.


Affected software

VMware ESXi
PowerFlex Appliance
PowerProtect DP Series Appliance (IDPA)
PowerFlex rack
IBM Cloud Pak System
Dell custom VMware ESXi

How to mitigate CVE-2024-22254

Install updates from vendor's website.

VMware ESXi - addressed in versions ESXi80U1d-23299997, ESXi80U2sb-23305545, ESXi70U3p-23307199
PowerFlex Appliance - update to IC-46.380.01
IBM Cloud Pak System - update to 2.3.4.1
PowerProtect DP Series Appliance (IDPA) - update to 2.7.7
PowerFlex rack - update to 3.6.6.0
Dell custom VMware ESXi - addressed in versions 7.0U3-A20, 8.0U2-A06

External References

Related Security Bulletins