CVE-2022-31696
published 2022-12-13CVE-2022-31696: VMware ESXi contains a memory corruption vulnerability that exists in the way it handles a network socket. A malicious actor with local access to ESXi may…
PriorityP342high8.8CVSS 3.1
AVLACLPRLUINSCCHIHAH
EPSS
0.34%
26.3th percentile
VMware ESXi contains a memory corruption vulnerability that exists in the way it handles a network socket. A malicious actor with local access to ESXi may exploit this issue to corrupt memory leading to an escape of the ESXi sandbox.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| vmware | cloud_foundation | — | — |
| vmware | cloud_foundation | — | — |
| vmware | cloud_foundation | — | — |
| vmware | cloud_foundation | — | — |
| vmware | cloud_foundation | — | — |
| vmware | cloud_foundation | — | — |
| vmware | cloud_foundation | — | — |
| vmware | cloud_foundation | >= 3.0 < 3.10 | 3.10 |
| vmware | cloud_foundation | >= 4.0 < 4.3.11 | 4.3.11 |
| vmware | esxi | — | — |
| vmware | esxi | — | — |
| vmware | esxi | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VMware
VMware ESXi and vCenter Server updates address multiple security vulnerabilities (CVE-2022-31696, CVE-2022-31697, CVE-2022-31698, CVE-2022-31699)
vendor_vmware·2022-12-08·CVSS 8.8
CVE-2022-31696 [HIGH] VMware ESXi and vCenter Server updates address multiple security vulnerabilities (CVE-2022-31696, CVE-2022-31697, CVE-2022-31698, CVE-2022-31699)
VMSA-2022-0030: VMware ESXi and vCenter Server updates address multiple security vulnerabilities (CVE-2022-31696, CVE-2022-31697, CVE-2022-31698, CVE-2022-31699)
VMware ESXi contains a memory corruption vulnerability that exists in the way it handles a network socket. VMware has evaluated the severity of this issue to be in the Important severity range with a maximum CVSSv3 base score of 7.5.
CVEs: CVE-2022-31696, CVE-2022-31697, CVE-2022-31698, CVE-2022-31699
Affected products: VMware Cloud Foundation, VMware ESXi, VMware vCenter Server, VMware vSphere
GHSA
GHSA-52m4-99w3-wq27: VMware ESXi contains a memory corruption vulnerability that exists in the way it handles a network socket
ghsa_unreviewed·2022-12-13
CVE-2022-31696 [HIGH] CWE-787 GHSA-52m4-99w3-wq27: VMware ESXi contains a memory corruption vulnerability that exists in the way it handles a network socket
VMware ESXi contains a memory corruption vulnerability that exists in the way it handles a network socket. A malicious actor with local access to ESXi may exploit this issue to corrupt memory leading to an escape of the ESXi sandbox.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-12-13
Published