TOCTOU Vulnerability in VMware ESXi Improper Handling of Temporary Files
CVE-2021-22043

7.5HIGH

Key Information:

Vendor
Vmware
Vendor
CVE Published:
16 February 2022

Summary

VMware ESXi is susceptible to a TOCTOU (Time-of-check Time-of-use) vulnerability that arises from insufficient safeguards in the handling of temporary files. This flaw can be exploited by attackers who have access to specific configurations, enabling them to write arbitrary files and thereby elevate their privileges within the system. This issue underscores the critical need for robust file handling mechanisms to mitigate potential exploitation risks.

Affected Version(s)

VMware ESXi and VMware Cloud Foundation VMware ESXi(7.0 U3 before ESXi70U3c-19193900, 7.0 U2 before ESXi70U2e-19290878 and 7.0 U1 before ESXi70U1e-19324898) and VMware Cloud Foundation 4.x before 4.4

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.