TOCTOU Vulnerability in VMware ESXi Improper Handling of Temporary Files
CVE-2021-22043
7.5HIGH
Key Information:
- Vendor
Vmware
- Vendor
- CVE Published:
- 16 February 2022
What is CVE-2021-22043?
VMware ESXi is susceptible to a TOCTOU (Time-of-check Time-of-use) vulnerability that arises from insufficient safeguards in the handling of temporary files. This flaw can be exploited by attackers who have access to specific configurations, enabling them to write arbitrary files and thereby elevate their privileges within the system. This issue underscores the critical need for robust file handling mechanisms to mitigate potential exploitation risks.
Affected Version(s)
VMware ESXi and VMware Cloud Foundation VMware ESXi(7.0 U3 before ESXi70U3c-19193900, 7.0 U2 before ESXi70U2e-19290878 and 7.0 U1 before ESXi70U1e-19324898) and VMware Cloud Foundation 4.x before 4.4