CVE-2024-22255: Information disclosure vulnerability
VMware ESXi, Workstation, and Fusion contain an information disclosure vulnerability in the UHCI USB controller. A malicious actor with administrative access to a virtual machine may be able to exploit this issue to leak memory from the vmx process.
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2024-22255?
CVE-2024-22255 has been classified as a critical severity vulnerability due to its potential for information disclosure.
How can I mitigate CVE-2024-22255?
To mitigate CVE-2024-22255, ensure that you update VMware ESXi, Workstation, and Fusion to the latest patched versions provided by VMware.
Who is affected by CVE-2024-22255?
CVE-2024-22255 affects users of VMware ESXi, Workstation, and Fusion who allow administrative access to virtual machines.
What is the nature of the vulnerability in CVE-2024-22255?
CVE-2024-22255 is an information disclosure vulnerability that can be exploited to leak sensitive memory data from the vmx process.
What should I do if I suspect exploitation of CVE-2024-22255?
If you suspect exploitation of CVE-2024-22255, immediately assess your environment for unauthorized access and update your VMware products without delay.