CVE-2024-22269: Infoleak
VMware Workstation and Fusion contain an information disclosure vulnerability in the vbluetooth device. A malicious actor with local administrative privileges on a virtual machine may be able to read privileged information contained in hypervisor memory from a virtual machine.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-22269?
CVE-2024-22269 is categorized as an information disclosure vulnerability with potential for serious impact if exploited.
How do I fix CVE-2024-22269?
To fix CVE-2024-22269, users should update to the latest version of VMware Workstation or Fusion that addresses this vulnerability.
Who is affected by CVE-2024-22269?
CVE-2024-22269 affects users of VMware Workstation and VMware Fusion who have local administrative privileges on a virtual machine.
What kind of information can be disclosed by CVE-2024-22269?
CVE-2024-22269 can potentially allow an attacker to read privileged information from hypervisor memory.
Is remote exploitation possible with CVE-2024-22269?
No, CVE-2024-22269 requires local administrative access on the virtual machine, so remote exploitation is not feasible.