Information disclosure vulnerability
CVE-2024-22255
7.1HIGH
Key Information:
- Vendor
- VMware
- Vendor
- CVE Published:
- 5 March 2024
Summary
VMware ESXi, Workstation, and Fusion have a vulnerability within the UHCI USB controller that may lead to information disclosure. If an attacker gains administrative access to a virtual machine, they could potentially exploit this vulnerability to extract sensitive memory content from the vmx process, posing risks to data confidentiality and system integrity. Users are advised to apply the latest security updates to mitigate the risks associated with this vulnerability.
Affected Version(s)
VMware Cloud Foundation 5.x
VMware Cloud Foundation 4.x
VMware ESXi 8.0
References
CVSS V3.1
Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved