CVE-2024-22251: Out-of-bounds read vulnerability
VMware Workstation and Fusion contain an out-of-bounds read vulnerability in the USB CCID (chip card interface device). A malicious actor with local administrative privileges on a virtual machine may trigger an out-of-bounds read leading to information disclosure.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-22251?
CVE-2024-22251 is classified as a medium severity vulnerability due to the potential for information disclosure.
How do I fix CVE-2024-22251?
To fix CVE-2024-22251, update to the latest version of VMware Workstation or VMware Fusion provided by VMware.
Who is affected by CVE-2024-22251?
CVE-2024-22251 affects users of VMware Workstation and VMware Fusion with local administrative privileges on a virtual machine.
What type of vulnerability is CVE-2024-22251?
CVE-2024-22251 is an out-of-bounds read vulnerability affecting the USB CCID component.
What could an attacker achieve with CVE-2024-22251?
An attacker could trigger an out-of-bounds read leading to information disclosure from the affected VMware products.