← Back

CVE-2022-31705

nvd nist
Published: Dec 14, 2022Modified: Jun 17, 2026

JSON object

Loading...
8.2
Vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Exploitability: 1.5 / Impact: 6.0
Source: NVD

Description

VMware ESXi, Workstation, and Fusion contain a heap out-of-bounds write vulnerability in the USB 2.0 controller (EHCI). A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host. On ESXi, the exploitation is contained within the VMX sandbox whereas, on Workstation and Fusion, this may lead to code execution on the machine where Workstation or Fusion is installed.

Affected (21)

3 products
Esxi
Workstation
Fusion
Configuration A
20 vulnerable
Vulnerable SoftwareAffected Versions
Vmware
Version 7.0
Version 7.0 beta
Version 7.0 update_1
Version 7.0 update_1a
Version 7.0 update_1b
Version 7.0 update_1c
Version 7.0 update_1d
Version 7.0 update_1e
Version 7.0 update_2
Version 7.0 update_2a
Version 7.0 update_2c
Version 7.0 update_2d
Version 7.0 update_2e
Version 7.0 update_3c
Version 7.0 update_3d
Version 7.0 update_3e
Version 7.0 update_3f
Version 7.0 update_3g
Version 8.0
From 16.0.0 to 16.2.5
Configuration B
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
From 12.0.0 to 12.2.5
Running on/withPlatform Versions
Apple
Mac Os X
All versions

References (2)

Source: security@vmware.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.