First published: Tue Jun 25 2024(Updated: )
VMware ESXi contains an out-of-bounds read vulnerability. A malicious actor with local administrative privileges on a virtual machine with an existing snapshot may trigger an out-of-bounds read leading to a denial-of-service condition of the host.
Credit: security@vmware.com
Affected Software | Affected Version | How to fix |
---|---|---|
VMware ESXi and Horizon DaaS |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-37086 is classified as having a high severity due to the potential for denial-of-service when exploited.
To mitigate CVE-2024-37086, apply the latest security patches provided by VMware for ESXi.
CVE-2024-37086 affects VMware ESXi installations with local administrative privileges on virtual machines with existing snapshots.
Exploitation of CVE-2024-37086 may lead to an out-of-bounds read, causing a denial-of-service condition on the ESXi host.
Currently, the best approach for CVE-2024-37086 is to update to the latest version of VMware ESXi that addresses the vulnerability.