← Back

CVE-2024-22253

nvd nist
Published: Mar 5, 2024Modified: Jun 17, 2026

JSON object

Loading...
6.7
Vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Exploitability: 0.8 / Impact: 5.9
Source: NVD

Description

VMware ESXi, Workstation, and Fusion contain a use-after-free vulnerability in the UHCI USB controller. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host. On ESXi, the exploitation is contained within the VMX sandbox whereas, on Workstation and Fusion, this may lead to code execution on the machine where Workstation or Fusion is installed.

Affected (37)

4 products
Cloud Foundation
Esxi
Workstation
Fusion
Configuration A
36 vulnerable
Vulnerable SoftwareAffected Versions
From 4.0 to 5.0
Vmware
Version 7.0.0 b
Version 7.0
Version 7.0 update_1
Version 7.0 update_1a
Version 7.0 update_1b
Version 7.0 update_1c
Version 7.0 update_1d
Version 7.0 update_1e
Version 7.0 update_2
Version 7.0 update_2a
Version 7.0 update_2c
Version 7.0 update_2d
Version 7.0 update_2e
Version 7.0 update_3
Version 7.0 update_3c
Version 7.0 update_3d
Version 7.0 update_3e
Version 7.0 update_3f
Version 7.0 update_3g
Version 7.0 update_3i
Version 7.0 update_3j
Version 7.0 update_3k
Version 7.0 update_3l
Version 7.0 update_3m
Version 7.0 update_3n
Version 7.0 update_3o
Version 8.0
Version 8.0 a
Version 8.0 b
Version 8.0 c
Version 8.0 update_1
Version 8.0 update_1a
Version 8.0 update_1c
Version 8.0 update_2
From 17.0.0 to 17.5.1
Configuration B
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
From 13.0.0 to 13.5.1
Running on/withPlatform Versions
Apple
Macos
All versions

References (2)

Source: security@vmware.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.