• News/
  • https://www.bleepingcomputer.com/news/security/vmware-fixes-critical-sandbox-escape-flaws-in-vmware-esxi-workstation-and-fusion/

VMware fixes critical sandbox escape flaws in VMware ESXi, Workstation, and Fusion

BleepingComputer
·
Bill Toulas
·
Published Mar 6, 2024
·
Updated

VMware released security updates to fix critical sandbox escape vulnerabilities in VMware ESXi, Workstation, Fusion, and Cloud Foundation products, allowing attackers to escape virtual machines and access the host operating system. These types of flaws are critical as they could permit attackers to gain unauthorized access to the host system where a hypervisor is installed or access other virtual machines running on the same host, breaching their isolation. The advisory outlines four vulnerabilities, tracked as CVE-2024-22252, CVE-2024-22253, CVE-2024-22254, and CVE-2024-22255, with CVSS v3 scores ranging from 7.1 to 9.3, but all with a critical severity rating. The four flaws can be summarized as follows: Impacted version products and fixed versions are listed in the table below:

A practical workaround to mitigate CVE-2024-22252, CVE-2024-22253, and CVE-2024-22255 is to remove USB controllers from virtual machines following the instructions provided by the vendor. Note that this may impact keyboard, mouse, and USB stick connectivity in some configurations. It is worth noting that VMware has made security fixes available for older ESXi versions (6.7U3u), 6.5 (6.5U3v), and VCF 3.x due to the vulnerabilities' severity. Finally, the vendor published a FAQ to accompany the bulletin, emphasizing the importance of prompt patching and providing guidance on response planning and workaround/fix implementation for specific products and configurations. VMware has neither observed nor ...

Read full article

Affected Software

5 affected components
VMware ESXi=6.7U3u
VMware ESXi=6.5U3v
VMware VMware Workstation
VMware VMware Fusion
VMware VMware Cloud Foundation=3.x
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses critical sandbox escape vulnerabilities fixed by VMware in their ESXi, Workstation, Fusion, and Cloud Foundation products.

2

What security implications are discussed?

The vulnerabilities allow attackers to escape from virtual machines and potentially access the host operating system.

3

What products are affected by these vulnerabilities?

The affected products include VMware ESXi versions 6.7U3u and 6.5U3v, VMware Workstation, VMware Fusion, and VMware Cloud Foundation 3.x.

4

What action did VMware take regarding these vulnerabilities?

VMware released security updates to address the critical sandbox escape vulnerabilities in their affected products.

5

Why is it important to update affected VMware products?

Updating affected VMware products is essential to protect against potential exploits that could compromise the host system.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203