cbcvebase.
CVE-2024-22252
published 2024-03-05

CVE-2024-22252: VMware ESXi, Workstation, and Fusion contain a use-after-free vulnerability in the XHCI USB controller. A malicious actor with local administrative privileges…

PriorityP182medium6.7CVSS 3.1
AVLACLPRHUINSUCHIHAH
ITWVulnCheck KEVRansomware
Exploited in the wild
EPSS
3.54%
88.0th percentile
VMware ESXi, Workstation, and Fusion contain a use-after-free vulnerability in the XHCI USB controller. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host. On ESXi, the exploitation is contained within the VMX sandbox whereas, on Workstation and Fusion, this may lead to code execution on the machine where Workstation or Fusion is installed.

Affected

5 ranges
VendorProductVersion rangeFixed in
vmwareesxi
vmwareesxi
vmwareesxi
vmwarefusion>= 13.0.0 < 13.5.113.5.1
vmwareworkstation>= 17.0.0 < 17.5.117.5.1

Detection & IOCsextracted from sources · hover to see the quote

hash31eec61ed6866e0b4b3d6b26a3a7d65fed040df61062dd468a1f5be8cc709de7
registryHKCU\Control Panel\Desktop\Wallpaper
registryHKLM\Software\Microsoft\Windows\CurrentVersion\OEMInformation
pathC:\ProgramData\.bmp
urlhxxps://getsession[.]org/
  • Detect Shinra ransomware persistence by monitoring for new executables dropped in the current user's startup folder with a 32 hex character filename
  • Detect ransomware activity by monitoring wevtutil.exe invocations used to enumerate and clear Windows event logs
  • CVE-2024-22252 exploitation targets the XHCI USB controller in VMware ESXi, Workstation, and Fusion; monitor VMX process for anomalous child process spawning or unexpected code execution on the host
  • ·The tweet claiming Socotra ransomware exploits CVE-2024-22252 is unverified; the CVE numbers cited in the tweet ('CVE-20204-22252') appear to be typos, and VMware had not confirmed active exploitation at time of advisory publication
  • ·VMware had not observed nor received reports of active exploitation of CVE-2024-22252 at the time of the advisory; exploitation requires local administrative privileges on a virtual machine
  • ·On ESXi, exploitation of CVE-2024-22252 is contained within the VMX sandbox, making the impact lower (CVSSv3 8.4) than on Workstation/Fusion (CVSSv3 9.3) where it may lead to host code execution

CVSS provenance

nvdv3.16.7MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
vulncheck9.3CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.