CVE-2024-22252
published 2024-03-05CVE-2024-22252: VMware ESXi, Workstation, and Fusion contain a use-after-free vulnerability in the XHCI USB controller. A malicious actor with local administrative privileges…
PriorityP182medium6.7CVSS 3.1
AVLACLPRHUINSUCHIHAH
ITWVulnCheck KEVRansomware
Exploited in the wild
EPSS
3.54%
88.0th percentile
VMware ESXi, Workstation, and Fusion contain a use-after-free vulnerability in the XHCI USB controller. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host. On ESXi, the exploitation is contained within the VMX sandbox whereas, on Workstation and Fusion, this may lead to code execution on the machine where Workstation or Fusion is installed.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| vmware | esxi | — | — |
| vmware | esxi | — | — |
| vmware | esxi | — | — |
| vmware | fusion | >= 13.0.0 < 13.5.1 | 13.5.1 |
| vmware | workstation | >= 17.0.0 < 17.5.1 | 17.5.1 |
Detection & IOCsextracted from sources · hover to see the quote
- →Detect Shinra ransomware persistence by monitoring for new executables dropped in the current user's startup folder with a 32 hex character filename ↗
- →Detect ransomware activity by monitoring wevtutil.exe invocations used to enumerate and clear Windows event logs ↗
- →CVE-2024-22252 exploitation targets the XHCI USB controller in VMware ESXi, Workstation, and Fusion; monitor VMX process for anomalous child process spawning or unexpected code execution on the host ↗
- ·The tweet claiming Socotra ransomware exploits CVE-2024-22252 is unverified; the CVE numbers cited in the tweet ('CVE-20204-22252') appear to be typos, and VMware had not confirmed active exploitation at time of advisory publication ↗
- ·VMware had not observed nor received reports of active exploitation of CVE-2024-22252 at the time of the advisory; exploitation requires local administrative privileges on a virtual machine ↗
- ·On ESXi, exploitation of CVE-2024-22252 is contained within the VMX sandbox, making the impact lower (CVSSv3 8.4) than on Workstation/Fusion (CVSSv3 9.3) where it may lead to host code execution ↗
CVSS provenance
nvdv3.16.7MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
vulncheck9.3CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-4xp8-3mc6-r83c: VMware ESXi, Workstation, and Fusion contain a use-after-free vulnerability in the XHCI USB controller
ghsa_unreviewed·2024-03-05
CVE-2024-22252 [CRITICAL] CWE-416 GHSA-4xp8-3mc6-r83c: VMware ESXi, Workstation, and Fusion contain a use-after-free vulnerability in the XHCI USB controller
VMware ESXi, Workstation, and Fusion contain a use-after-free vulnerability in the XHCI USB controller. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host. On ESXi, the exploitation is contained within the VMX sandbox whereas, on Workstation and Fusion, this may lead to code execution on the machine where Workstation or Fusion is installed.
VulnCheck
VMware ESXi, Workstation, and Fusion XHCI USB Controller Vulnerability
vulncheck·2024·CVSS 9.3
CVE-2024-22252 [CRITICAL] VMware ESXi, Workstation, and Fusion XHCI USB Controller Vulnerability
VMware ESXi, Workstation, and Fusion XHCI USB Controller Vulnerability
VMware ESXi, Workstation, and Fusion contain a use-after-free vulnerability in the XHCI USB controller. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host. On ESXi, the exploitation is contained within the VMX sandbox whereas, on Workstation and Fusion, this may lead to code execution on the machine where Workstation or Fusion is installed.
Affected: VMware ESXi, Workstation, and Fusion
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Known Ransomware Campaign Use: Known
Exploitation Referen
VMware
VMware ESXi, Workstation, and Fusion updates address multiple security vulnerabilities (CVE-2024-22252, CVE-2024-22253, CVE-2024-22254, CVE-2024-22255)
vendor_vmware·2024-03-05·CVSS 9.3
CVE-2024-22252 [CRITICAL] VMware ESXi, Workstation, and Fusion updates address multiple security vulnerabilities (CVE-2024-22252, CVE-2024-22253, CVE-2024-22254, CVE-2024-22255)
VMSA-2024-0006: VMware ESXi, Workstation, and Fusion updates address multiple security vulnerabilities (CVE-2024-22252, CVE-2024-22253, CVE-2024-22254, CVE-2024-22255)
VMware ESXi, Workstation, and Fusion contain a use-after-free vulnerability in the XHCI USB controller. VMware has evaluated the severity of this issue to be in the Critical severity range with a maximum CVSSv3 base score of 9.3 for Workstation/Fusion and in the Important severity range with a maximum CVSSv3 base score of 8.4 for ESXi.
CVEs: CVE-2024-22252, CVE-2024-22253, CVE-2024-22254, CVE-2024-22255
Affected products: Fusion Pro, VMware Cloud Foundation, VMware ESXi, VMware Fusion, VMware Workstation, Workstation Pro, vSphere
No detection rules found.
No public exploits indexed.
Fortinet
Ransomware Roundup – Shinra and Limpopo Ransomware | FortiGuard Labs
blogs_fortinet·2024-06-14
Ransomware Roundup – Shinra and Limpopo Ransomware | FortiGuard Labs
FORTIGUARD LABS THREAT RESEARCH
Ransomware Roundup – Shinra and Limpopo Ransomware
By Shunichi Imano and Fred Gutierrez | June 14, 2024
FortiGuard Labs gathers data on ransomware variants of interest that have been gaining traction within our datasets and the OSINT community. The Ransomware Roundup report aims to provide readers with brief insights into the evolving ransomware landscape and the Fortinet solutions that protect against those variants.
This edition of the Ransomware Roundup covers the Shinra and Limpopo ransomware.
Affected platforms: Microsoft Windows, VMWare ESXi
Impacted parties: Microsoft Windows and VMWare ESXi Users
Impact: Encrypts victims' files and demands ransom for file decryption
Severity level: High
Shinra Ransomware Overview
The Shinra ransomware was first
Checkpoint
11th March – Threat Intelligence Report
blogs_checkpoint·2024-03-11·CVSS 8.2
CVE-2023-46805 [HIGH] 11th March – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 11th March – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 11th March, please download our Threat_Intelligence Bulletin .
TOP ATTACKS AND BREACHES
Cybersecurity and Infrastructure Security Agency (CISA) has taken offline two systems following a breach that occurred as a result of the recent vulnerabilities exploitation in Ivanti products. The affected systems potentially include the Infrastructure Protection Gateway and the Chemical Security Assessment Tool, holding sen
Bleepingcomputer
VMware fixes critical sandbox escape flaws in ESXi, Workstation, and Fusion
blogs_bleepingcomputer·2024-03-06·CVSS 9.3
[CRITICAL] VMware fixes critical sandbox escape flaws in ESXi, Workstation, and Fusion
## VMware fixes critical sandbox escape flaws in ESXi, Workstation, and Fusion
## Bill Toulas
VMware released security updates to fix critical sandbox escape vulnerabilities in VMware ESXi, Workstation, Fusion, and Cloud Foundation products, allowing attackers to escape virtual machines and access the host operating system.
These types of flaws are critical as they could permit attackers to gain unauthorized access to the host system where a hypervisor is installed or access other virtual machines running on the same host, breaching their isolation.
The advisory outlines four vulnerabilities , tracked as CVE-2024-22252, CVE-2024-22253, CVE-2024-22254, and CVE-2024-22255, with CVSS v3 scores ranging from 7.1 to 9.3, but all with a critical severity rating.
The four flaws can be summari
2024-03-05
Published
Exploited in the wild