First published: Tue May 21 2024(Updated: )
The storage controllers on VMware ESXi, Workstation, and Fusion have out-of-bounds read/write vulnerability. A malicious actor with access to a virtual machine with storage controllers enabled may exploit this issue to create a denial of service condition or execute code on the hypervisor from a virtual machine in conjunction with other issues.
Credit: security@vmware.com
Affected Software | Affected Version | How to fix |
---|---|---|
VMware ESXi | ||
VMware Workstation | ||
VMware Fusion Pro |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-22273 has been classified as a critical vulnerability due to the potential for remote code execution and denial of service.
To fix CVE-2024-22273, update to the latest version of VMware ESXi, Workstation, or Fusion that contains the security patch.
CVE-2024-22273 affects VMware ESXi, Workstation, and Fusion products with storage controllers enabled.
Yes, exploiting CVE-2024-22273 can create a denial of service condition on the hypervisor.
A malicious actor with access to a virtual machine with storage controllers enabled can exploit CVE-2024-22273.