CVE-2022-31681
published 2022-10-07CVE-2022-31681: VMware ESXi contains a null-pointer deference vulnerability. A malicious actor with privileges within the VMX process only, may create a denial of service…
PriorityP421medium6.5CVSS 3.1
AVLACLPRLUINSCCNINAH
EPSS
0.20%
9.9th percentile
VMware ESXi contains a null-pointer deference vulnerability. A malicious actor with privileges within the VMX process only, may create a denial of service condition on the host.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| vmware | cloud_foundation | — | — |
| vmware | cloud_foundation | — | — |
| vmware | cloud_foundation | — | — |
| vmware | cloud_foundation | >= 4.2 < 4.3.1.1 | 4.3.1.1 |
| vmware | esxi | < 7.0 | 7.0 |
| vmware | esxi | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VMware
VMware ESXi and vCenter Server updates address multiple security vulnerabilities (CVE-2022-31680, CVE-2022-31681)
vendor_vmware·2022-10-06·CVSS 9.1
CVE-2022-31680 [CRITICAL] VMware ESXi and vCenter Server updates address multiple security vulnerabilities (CVE-2022-31680, CVE-2022-31681)
VMSA-2022-0025: VMware ESXi and vCenter Server updates address multiple security vulnerabilities (CVE-2022-31680, CVE-2022-31681)
The vCenter Server contains an unsafe deserialisation vulnerability in the PSC (Platform services controller). VMware has evaluated the severity of this issue to be in the Important severity range with a maximum CVSSv3 base score of 7.2.
CVEs: CVE-2022-31680, CVE-2022-31681
Affected products: VMware Cloud Foundation, VMware ESXi, VMware vCenter Server, VMware vSphere
GHSA
GHSA-5996-c7cm-2xrf: VMware ESXi contains a null-pointer deference vulnerability
ghsa_unreviewed·2022-10-08
CVE-2022-31681 [MEDIUM] CWE-476 GHSA-5996-c7cm-2xrf: VMware ESXi contains a null-pointer deference vulnerability
VMware ESXi contains a null-pointer deference vulnerability. A malicious actor with privileges within the VMX process only, may create a denial of service condition on the host.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-10-07
Published