CVE-2021-22043: High severity vmware fusion vulnerability
Published Feb 16, 2022
·Updated
VMware ESXi contains a TOCTOU (Time-of-check Time-of-use) vulnerability that exists in the way temporary files are handled. A malicious actor with access to settingsd, may exploit this issue to escalate their privileges by writing arbitrary files.
Affected Software
4 affected components
VMware Fusion<4.4
VMware ESXi=7.0-update_1
VMware ESXi=7.0-update_2
VMware ESXi=7.0-update_3
Remediation
Event History
Feb 16, 2022
CVE Published
via MITRE·04:37 PM
Data Sourced
via MITRE·04:37 PM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2021-22043?
CVE-2021-22043 is a TOCTOU vulnerability in VMware ESXi that allows a malicious actor to escalate privileges by writing arbitrary files.
2
How does CVE-2021-22043 affect VMware Fusion?
CVE-2021-22043 affects VMware Fusion version 4.4 and prior.
3
How does CVE-2021-22043 affect VMware ESXi?
CVE-2021-22043 affects VMware ESXi version 7.0-update_1, 7.0-update_2, and 7.0-update_3.
4
What is the severity of CVE-2021-22043?
CVE-2021-22043 has a severity value of 7.5 (high).
5
Is there a fix available for CVE-2021-22043?
Yes, VMware has released a security advisory (VMSA-2022-0004) that provides the necessary patches to address the vulnerability.