cbcvebase.
CVE-2021-22045
published 2022-01-04

CVE-2021-22045: VMware ESXi (7.0, 6.7 before ESXi670-202111101-SG and 6.5 before ESXi650-202110101-SG), VMware Workstation (16.2.0) and VMware Fusion (12.2.0) contains a…

PriorityP347high7.8CVSS 3.1
AVLACHPRLUINSCCHIHAH
EPSS
4.68%
90.8th percentile
VMware ESXi (7.0, 6.7 before ESXi670-202111101-SG and 6.5 before ESXi650-202110101-SG), VMware Workstation (16.2.0) and VMware Fusion (12.2.0) contains a heap-overflow vulnerability in CD-ROM device emulation. A malicious actor with access to a virtual machine with CD-ROM device emulation may be able to exploit this vulnerability in conjunction with other issues to execute code on the hypervisor from a virtual machine.

Affected

7 ranges
VendorProductVersion rangeFixed in
vmwarecloud_foundation3.0 – 3.10.2.2
vmwarecloud_foundation4.0 – 4.3.1
vmwareesxi
vmwareesxi
vmwareesxi
vmwarefusion>= 12.0.0 < 12.2.012.2.0
vmwareworkstation>= 16.0.0 < 16.2.016.2.0

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
nvdv2.06.9MEDIUMAV:L/AC:M/Au:N/C:C/I:C/A:C
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.