Lucene search

K
cveVmwareCVE-2024-22270
HistoryMay 14, 2024 - 4:16 p.m.

CVE-2024-22270

2024-05-1416:16:12
CWE-200
vmware
web.nvd.nist.gov
41
vmware
information disclosure
file sharing
vulnerability
administrative privileges
hypervisor memory

CVSS3

7.1

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N

AI Score

7.2

Confidence

High

EPSS

0.001

Percentile

28.8%

VMware Workstation and Fusion contain an information disclosure vulnerability in the Host Guest File Sharing (HGFS) functionality. A malicious actor with local administrative privileges on a virtual machine may be able to read privileged information contained in hypervisor memory from a virtual machine.

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "platforms": [
      "Windows",
      "Linux"
    ],
    "product": "VMware Workstation",
    "vendor": "N/A",
    "versions": [
      {
        "lessThan": "17.5.2",
        "status": "affected",
        "version": "17.x",
        "versionType": "custom"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "platforms": [
      "MacOS"
    ],
    "product": "VMware Fusion",
    "vendor": "N/A",
    "versions": [
      {
        "lessThan": "13.5.2",
        "status": "affected",
        "version": "13.x",
        "versionType": "custom"
      }
    ]
  }
]

CVSS3

7.1

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N

AI Score

7.2

Confidence

High

EPSS

0.001

Percentile

28.8%