Security News > 2022 > December > VMware fixes critical ESXi and vRealize security flaws

VMware fixes critical ESXi and vRealize security flaws
2022-12-14 17:46

VMware released security updates to address a critical-severity vulnerability impacting ESXi, Workstation, Fusion, and Cloud Foundation, and a critical-severity command injection flaw affecting vRealize Network Insight.

The VMware ESXi heap out-of-bounds write vulnerability is tracked as CVE-2022-31705 and has received a CVSS v3 severity rating of 9.3.

"A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host," mentions the security advisory.

VMware has released step-by-step instructions on how to apply the workaround on a VMware ESXi virtual machine, which also applies to the Cloud Foundation suite.

On a separate security bulletin, VMware gives details about CVE-2022-31702, a critical severity vulnerability that allows command injection in the vRNI REST API of vRealize Network Insight versions 6.2 to 6.7.

VMware vRealize Network Insight 6.8.0 is not affected by these vulnerabilities.


News URL

https://www.bleepingcomputer.com/news/security/vmware-fixes-critical-esxi-and-vrealize-security-flaws/

Related Vulnerability

DATE CVE VULNERABILITY TITLE RISK
2022-12-14 CVE-2022-31705 Out-of-bounds Write vulnerability in VMWare Esxi, Fusion and Workstation
VMware ESXi, Workstation, and Fusion contain a heap out-of-bounds write vulnerability in the USB 2.0 controller (EHCI).
local
low complexity
vmware CWE-787
8.2
2022-12-14 CVE-2022-31702 Command Injection vulnerability in VMWare Vrealize Network Insight
vRealize Network Insight (vRNI) contains a command injection vulnerability present in the vRNI REST API.
network
low complexity
vmware CWE-77
critical
9.8

Related vendor

VENDOR LAST 12M #/PRODUCTS LOW MEDIUM HIGH CRITICAL TOTAL VULNS
Vmware 146 11 222 256 102 591