CVE-2024-37086: Medium severity vmware esxi and horizon daas vulnerability
VMware ESXi contains an out-of-bounds read vulnerability. A malicious actor with local administrative privileges on a virtual machine with an existing snapshot may trigger an out-of-bounds read leading to a denial-of-service condition of the host.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-37086?
CVE-2024-37086 is classified as having a high severity due to the potential for denial-of-service when exploited.
How do I fix CVE-2024-37086?
To mitigate CVE-2024-37086, apply the latest security patches provided by VMware for ESXi.
Who is affected by CVE-2024-37086?
CVE-2024-37086 affects VMware ESXi installations with local administrative privileges on virtual machines with existing snapshots.
What is the impact of CVE-2024-37086?
Exploitation of CVE-2024-37086 may lead to an out-of-bounds read, causing a denial-of-service condition on the ESXi host.
Is there a workaround for CVE-2024-37086?
Currently, the best approach for CVE-2024-37086 is to update to the latest version of VMware ESXi that addresses the vulnerability.