Skip to main content

VMSA-2022-0033 Advisory for CVE-2022-31705 - Heap out-of-bounds write vulnerability in EHCI controller


dips
Forum|alt.badge.img+7
  • Veeam Legend
  • 808 comments

VMware have released an advisory for CVE-2022-31705 just in time for the weekend!

Impacted Products:

  • VMware ESXi 
  • VMware Workstation Pro / Player (Workstation) 
  • VMware Fusion Pro / Fusion (Fusion)
  • VMware Cloud Foundation

Description

VMware ESXi, Workstation, and Fusion contain a heap out-of-bounds write vulnerability in the USB 2.0 controller (EHCI). VMware has evaluated the severity of this issue to be in the Critical severity range with a maximum CVSSv3 base score of 9.3.

Known Attack Vectors

A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host. On ESXi, the exploitation is contained within the VMX sandbox whereas, on Workstation and Fusion, this may lead to code execution on the machine where Workstation or Fusion is installed.

 

More here: https://www.vmware.com/security/advisories/VMSA-2022-0033.html

3 comments

marcofabbri
Forum|alt.badge.img+13
  • On the path to Greatness
  • 990 comments
  • December 16, 2022

9.3 fortunately isn’t for ESXI 😀

Just to dissipate some panic and have a nice weekend😂

Interesting is that 6.5 isn’t affected.


Chris.Childerhose
Forum|alt.badge.img+21
  • Veeam Legend, Veeam Vanguard
  • 8506 comments
  • December 16, 2022

Wonderful to have that before the weekend and so close to the holidays.  Time to inform the VMware team.


dips
Forum|alt.badge.img+7
  • Author
  • Veeam Legend
  • 808 comments
  • December 19, 2022

Not the best of times but hopefully it is a bit quieter as well for some patching


Comment