ZDI-23-522: (Pwn2Own) VMware Workstation UHCI Component Stack-based Buffer Overflow Local Privilege Escalation Vulnerability
This vulnerability allows local attackers to escalate privileges on affected installations of VMware Workstation. An attacker must first obtain the ability to execute high-privileged code on the target guest system in order to exploit this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-23-522?
The severity of ZDI-23-522 is considered high due to its potential to allow local privilege escalation.
How do I fix ZDI-23-522?
To fix ZDI-23-522, update VMware Workstation to the latest version provided by VMware that addresses this vulnerability.
Who is affected by ZDI-23-522?
ZDI-23-522 affects all installations of VMware Workstation that do not have the latest security patches applied.
What type of attack does ZDI-23-522 exploit?
ZDI-23-522 can be exploited by local attackers to escalate privileges after gaining high-privileged code execution on the guest system.
Is ZDI-23-522 a remote vulnerability?
No, ZDI-23-522 is a local vulnerability that requires an attacker to have access to the target guest system.