ZDI-24-527: (Pwn2Own) VMWare Workstation VBluetoothHCI_PacketOut Use-After-Free Privilege Escalation Vulnerability
This vulnerability allows local attackers to escalate privileges on affected installations of VMWare Workstation. An attacker must first obtain the ability to execute high-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.2. The following CVEs are assigned: CVE-2024-22267.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-24-527?
The CVSS rating for ZDI-24-527 indicates a critical severity level, making it a significant risk to affected systems.
How do I fix ZDI-24-527?
To resolve ZDI-24-527, users should apply the latest security updates provided by VMWare for Workstation.
Who is affected by ZDI-24-527?
The vulnerability ZDI-24-527 affects installations of VMWare Workstation on local systems.
What are the potential consequences of exploiting ZDI-24-527?
Exploiting ZDI-24-527 can allow local attackers to escalate privileges, leading to unauthorized system control.
What conditions are needed to exploit ZDI-24-527?
An attacker must first have the ability to execute high-privileged code on the target system to exploit ZDI-24-527.