First published: Tue Feb 27 2024(Updated: )
VMware Workstation and Fusion contain an out-of-bounds read vulnerability in the USB CCID (chip card interface device). A malicious actor with local administrative privileges on a virtual machine may trigger an out-of-bounds read leading to information disclosure.
Credit: security@vmware.com
Affected Software | Affected Version | How to fix |
---|---|---|
VMware Workstation | ||
VMware Fusion Pro |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-22251 is classified as a medium severity vulnerability due to the potential for information disclosure.
To fix CVE-2024-22251, update to the latest version of VMware Workstation or VMware Fusion provided by VMware.
CVE-2024-22251 affects users of VMware Workstation and VMware Fusion with local administrative privileges on a virtual machine.
CVE-2024-22251 is an out-of-bounds read vulnerability affecting the USB CCID component.
An attacker could trigger an out-of-bounds read leading to information disclosure from the affected VMware products.