ZDI-CAN-23847: ZDI-24-527: (Pwn2Own) VMWare Workstation VBluetoothHCI_PacketOut Use-After-Free Privilege Escalation Vulnerability
This vulnerability allows local attackers to escalate privileges on affected installations of VMWare Workstation. An attacker must first obtain the ability to execute high-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.2. The following CVEs are assigned: CVE-2024-22267.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-23847?
The severity of ZDI-CAN-23847 is assessed using the CVSS rating, focusing on potential privilege escalation risks.
How do I fix ZDI-CAN-23847?
To fix ZDI-CAN-23847, ensure that you update VMware Workstation to the latest patched version provided by VMware.
Who is affected by ZDI-CAN-23847?
ZDI-CAN-23847 affects users of VMware Workstation where local attackers can escalate privileges.
Can ZDI-CAN-23847 be exploited remotely?
No, ZDI-CAN-23847 requires the attacker to have local access to the machine to exploit the vulnerability.
What kind of impact does ZDI-CAN-23847 have on affected systems?
ZDI-CAN-23847 can allow attackers to gain higher privileges, potentially compromising the system's integrity and security.