First published: Tue May 14 2024(Updated: )
VMware Workstation and Fusion contain a heap buffer-overflow vulnerability in the Shader functionality. A malicious actor with non-administrative access to a virtual machine with 3D graphics enabled may be able to exploit this vulnerability to create a denial of service condition.
Credit: security@vmware.com
Affected Software | Affected Version | How to fix |
---|---|---|
VMware Workstation and ESXi | ||
VMware Fusion | ||
All of | ||
VMware Workstation and ESXi | >=17.0.0<17.5.2 | |
Microsoft Windows Operating System | ||
All of | ||
VMware Fusion | >=13.0.0<13.5.2 | |
macOS |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-22268 is considered a critical vulnerability due to its potential to cause a denial of service condition.
To mitigate CVE-2024-22268, users should update to the latest version of VMware Workstation or Fusion that addresses this security flaw.
CVE-2024-22268 affects users of VMware Workstation and VMware Fusion with 3D graphics enabled.
CVE-2024-22268 is a heap buffer-overflow vulnerability found in the shader functionality of VMware products.
Yes, a malicious actor with non-administrative access to a virtual machine can exploit CVE-2024-22268.