Lucene search

K
vulnrichmentVmwareVULNRICHMENT:CVE-2024-22267
HistoryMay 14, 2024 - 12:58 p.m.

CVE-2024-22267

2024-05-1412:58:31
vmware
github.com
11
vmware
workstation
fusion
use-after-free
vulnerability
vbluetooth
local administrative privileges
virtual machine
vmx process
code execution

CVSS3

9.3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

AI Score

7.2

Confidence

Low

EPSS

0.001

Percentile

28.8%

SSVC

Exploitation

None

Automatable

No

Technical Impact

Total

VMware Workstation and Fusion contain a use-after-free vulnerability in the vbluetooth device. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine’s VMX process running on the host.

ADP Affected

[
  {
    "cpes": [
      "cpe:2.3:a:vmware:vmware_workstation:17.0:*:*:*:*:*:*:*"
    ],
    "vendor": "vmware",
    "product": "vmware_workstation",
    "versions": [
      {
        "status": "affected",
        "version": "17.0",
        "lessThan": "17.5.2",
        "versionType": "custom"
      }
    ],
    "defaultStatus": "unknown"
  },
  {
    "cpes": [
      "cpe:2.3:a:vmware:fusion:13.0.0:*:*:*:*:*:*:*"
    ],
    "vendor": "vmware",
    "product": "fusion",
    "versions": [
      {
        "status": "affected",
        "version": "13.0.0",
        "lessThan": "13.5.2",
        "versionType": "custom"
      }
    ],
    "defaultStatus": "unknown"
  }
]

CVSS3

9.3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

AI Score

7.2

Confidence

Low

EPSS

0.001

Percentile

28.8%

SSVC

Exploitation

None

Automatable

No

Technical Impact

Total

Related for VULNRICHMENT:CVE-2024-22267