#VU60617 Race condition in VMware ESXi - CVE-2021-22041
Published: February 15, 2022
VMware ESXi
VMware, Inc
Description
The vulnerability allows a remote user to escalate privileges on the system.
The vulnerability exists due to a double-fetch vulnerability in the UHCI USB controller. A remote user with administrative permissions on the guest OS can
trigger a race condition and execute arbitrary code as the virtual
machine's VMX process running on the host.
Successful exploitation of the vulnerability may allow an attacker to compromise the hypervisor.