• Menu
  • Skip to main content
  • Skip to primary sidebar

The Cyber Security News

Latest Cyber Security News

Header Right

  • Latest News
  • Vulnerabilities
  • Cloud Services
vmware issues security patches for esxi, workstation, and fusion flaws

VMware Issues Security Patches for ESXi, Workstation, and Fusion Flaws

You are here: Home / General Cyber Security News / VMware Issues Security Patches for ESXi, Workstation, and Fusion Flaws
March 6, 2024

VMware has launched patches to tackle four security flaws impacting ESXi, Workstation, and Fusion, which includes two critical flaws that could lead to code execution.

Tracked as CVE-2024-22252 and CVE-2024-22253, the vulnerabilities have been explained as use-right after-free bugs in the XHCI USB controller. They have a CVSS rating of 9.3 for Workstation and Fusion, and 8.4 for ESXi methods.

“A malicious actor with nearby administrative privileges on a digital device may exploit this issue to execute code as the virtual machine’s VMX approach jogging on the host,” the enterprise said in a new advisory.

✔ Approved Seller From Our Partners
Mullvad VPN Discount

Protect your privacy by Mullvad VPN. Mullvad VPN is one of the famous brands in the security and privacy world. With Mullvad VPN you will not even be asked for your email address. No log policy, no data from you will be saved. Get your license key now from the official distributor of Mullvad with discount: SerialCart® (Limited Offer).

➤ Get Mullvad VPN with 12% Discount


“On ESXi, the exploitation is contained inside the VMX sandbox whilst, on Workstation and Fusion, this may direct to code execution on the equipment the place Workstation or Fusion is installed.”

Many security researchers affiliated with the Ant Team Gentle-Calendar year Security Lab and QiAnXin have been credited with independently discovering and reporting CVE-2024-22252. Security scientists VictorV and Wei have been acknowledged for reporting CVE-2024-22253.

Cybersecurity

Also patched by the Broadcom-owned virtualization expert services supplier are two other shortcomings –

  • CVE-2024-22254 (CVSS rating: 7.9) – An out-of-bounds generate vulnerability in ESXi that a destructive actor with privileges within just the VMX approach could exploit to cause a sandbox escape.
  • CVE-2024-22255 (CVSS rating: 7.9) – An information and facts disclosure vulnerability in the UHCI USB controller that an attacker with administrative access to a digital equipment may possibly exploit to leak memory from the vmx course of action.

The issues have been dealt with in the next variations, including people that have reached stop-of-everyday living (EoL) because of to the severity of these issues –

  • ESXi 6.5 – 6.5U3v
  • ESXi 6.7 – 6.7U3u
  • ESXi 7. – ESXi70U3p-23307199
  • ESXi 8. – ESXi80U2sb-23305545 and ESXi80U1d-23299997
  • VMware Cloud Foundation (VCF) 3.x
  • Workstation 17.x – 17.5.1
  • Fusion 13.x (macOS) – 13.5.1

Cybersecurity

As a short-term workaround till a patch can be deployed, shoppers have been requested to take out all USB controllers from the virtual device.

“In addition, digital/emulated USB units, this sort of as VMware virtual USB adhere or dongle, will not be available for use by the digital device,” the business claimed. “In contrast, the default keyboard/mouse as enter units are not influenced as they are, by default, not connected by USB protocol but have a driver that does computer software system emulation in the guest OS.”

Uncovered this posting exciting? Follow us on Twitter  and LinkedIn to examine more exclusive content material we write-up.


Some pieces of this short article are sourced from:
thehackernews.com

Previous Post: «alert: ghostsec and stormous launch joint ransomware attacks in over Alert: GhostSec and Stormous Launch Joint Ransomware Attacks in Over 15 Countries
Next Post: U.S. Cracks Down on Predatory Spyware Firm for Targeting Officials and Journalists u.s. cracks down on predatory spyware firm for targeting officials»

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

Report This Article

Recent Posts

  • Zero-Click Agentic Browser Attack Can Delete Entire Google Drive Using Crafted Emails
  • Critical XXE Bug CVE-2025-66516 (CVSS 10.0) Hits Apache Tika, Requires Urgent Patch
  • Chinese Hackers Have Started Exploiting the Newly Disclosed React2Shell Vulnerability
  • Intellexa Leaks Reveal Zero-Days and Ads-Based Vector for Predator Spyware Delivery
  • “Getting to Yes”: An Anti-Sales Guide for MSPs
  • CISA Reports PRC Hackers Using BRICKSTORM for Long-Term Access in U.S. Systems
  • JPCERT Confirms Active Command Injection Attacks on Array AG Gateways
  • Silver Fox Uses Fake Microsoft Teams Installer to Spread ValleyRAT Malware in China
  • ThreatsDay Bulletin: Wi-Fi Hack, npm Worm, DeFi Theft, Phishing Blasts— and 15 More Stories
  • 5 Threats That Reshaped Web Security This Year [2025]

Copyright © TheCyberSecurity.News, All Rights Reserved.