Want relief keeping up with product patching, upgrades, and more? Learn how our Managed Services for law firms can help you.
VMWare ESXi 7.0 & ESXi 8.0 Multiple Vulnerabilities
March 2024
Please see more details on ESXi v7.0 and v8.0 vulnerabilities below.
Identified Vulnerabilities
- Use-after-free vulnerability in XHCI USB controller (CVE-2024-22252)
- Use-after-free vulnerability in UHCI USB controller (CVE-2024-22253)
- Out-of-bounds write vulnerability (CVE-2024-22254)
- Information disclosure vulnerability in UHCI USB controller (CVE-2024-22255)
A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine’s VMX process running on the host. On ESXi, the exploitation is contained within the VMX sandbox
Patch and Upgrade Available
Apply “Fixed Version” suggested by VMWare.
Specific mitigation and workarounds are made available at VMWare’s advisory knowledge base.
Sources
- https://www.vmware.com/security/advisories/VMSA-2024-0006.html
- https://docs.vmware.com/en/VMware-vSphere/8.0/rn/vsphere-esxi-80u2b-release-notes/index.html
- https://docs.vmware.com/en/VMware-vSphere/8.0/rn/vsphere-esxi-80u1d-release-notes/index.html
- https://docs.vmware.com/en/VMware-vSphere/7.0/rn/vsphere-esxi-70u3p-release-notes/index.html
Contact Cornerstone.IT for assistance with this or any other technology or security needs.