CVE-2024-22253
published 2024-03-05CVE-2024-22253: VMware ESXi, Workstation, and Fusion contain a use-after-free vulnerability in the UHCI USB controller. A malicious actor with local administrative privileges…
PriorityP183medium6.7CVSS 3.1
AVLACLPRHUINSUCHIHAH
ITWVulnCheck KEVRansomware
Exploited in the wild
EPSS
0.65%
46.9th percentile
VMware ESXi, Workstation, and Fusion contain a use-after-free vulnerability in the UHCI USB controller. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host. On ESXi, the exploitation is contained within the VMX sandbox whereas, on Workstation and Fusion, this may lead to code execution on the machine where Workstation or Fusion is installed.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| vmware | cloud_foundation | 4.0 – 5.0 | — |
| vmware | esxi | — | — |
| vmware | esxi | — | — |
| vmware | esxi | — | — |
| vmware | fusion | >= 13.0.0 < 13.5.1 | 13.5.1 |
| vmware | workstation | >= 17.0.0 < 17.5.1 | 17.5.1 |
Detection & IOCsextracted from sources · hover to see the quote
- →Detect Shinra ransomware by monitoring wevtutil.exe invocations used to enumerate and clear Windows event logs ↗
- →CVE-2024-22253 targets the UHCI USB controller; detect exploitation attempts by monitoring VMX process anomalies or unexpected code execution from VMX sandbox on ESXi hosts ↗
- →Shinra ransomware copies itself to the current user's startup folder as a 32-hex-character named .exe; monitor startup folder for newly created executables matching this pattern ↗
- ·The Fortinet report notes the CVE numbers in the tweet referencing exploitation may contain a typo ('CVE-20204-22252' and 'CVE-20204-22253'), and exploitation of CVE-2024-22253 by Socotra/Limpopo ransomware is unverified ↗
- ·VMware had not observed nor received reports of active exploitation of CVE-2024-22253 at time of advisory publication ↗
- ·CVE-2024-22253 exploitation on ESXi is contained within the VMX sandbox, but on Workstation and Fusion it may lead to full host code execution — detection and response scope differs by platform ↗
CVSS provenance
nvdv3.16.7MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
vulncheck9.3CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-57rg-p28x-x2f6: VMware ESXi, Workstation, and Fusion contain a use-after-free vulnerability in the UHCI USB controller
ghsa_unreviewed·2024-03-05
CVE-2024-22253 [CRITICAL] CWE-416 GHSA-57rg-p28x-x2f6: VMware ESXi, Workstation, and Fusion contain a use-after-free vulnerability in the UHCI USB controller
VMware ESXi, Workstation, and Fusion contain a use-after-free vulnerability in the UHCI USB controller. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host. On ESXi, the exploitation is contained within the VMX sandbox whereas, on Workstation and Fusion, this may lead to code execution on the machine where Workstation or Fusion is installed.
VulnCheck
VMware ESXi, Workstation, and Fusion UHCI USB Controller Vulnerability
vulncheck·2024·CVSS 9.3
CVE-2024-22253 [CRITICAL] VMware ESXi, Workstation, and Fusion UHCI USB Controller Vulnerability
VMware ESXi, Workstation, and Fusion UHCI USB Controller Vulnerability
VMware ESXi, Workstation, and Fusion contain a use-after-free vulnerability in the UHCI USB controller. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host. On ESXi, the exploitation is contained within the VMX sandbox whereas, on Workstation and Fusion, this may lead to code execution on the machine where Workstation or Fusion is installed.
Affected: VMware ESXi, Workstation, and Fusion
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Known Ransomware Campaign Use: Known
Exploitation Referen
VMware
VMware ESXi, Workstation, and Fusion updates address multiple security vulnerabilities (CVE-2024-22252, CVE-2024-22253, CVE-2024-22254, CVE-2024-22255)
vendor_vmware·2024-03-05·CVSS 9.3
CVE-2024-22252 [CRITICAL] VMware ESXi, Workstation, and Fusion updates address multiple security vulnerabilities (CVE-2024-22252, CVE-2024-22253, CVE-2024-22254, CVE-2024-22255)
VMSA-2024-0006: VMware ESXi, Workstation, and Fusion updates address multiple security vulnerabilities (CVE-2024-22252, CVE-2024-22253, CVE-2024-22254, CVE-2024-22255)
VMware ESXi, Workstation, and Fusion contain a use-after-free vulnerability in the XHCI USB controller. VMware has evaluated the severity of this issue to be in the Critical severity range with a maximum CVSSv3 base score of 9.3 for Workstation/Fusion and in the Important severity range with a maximum CVSSv3 base score of 8.4 for ESXi.
CVEs: CVE-2024-22252, CVE-2024-22253, CVE-2024-22254, CVE-2024-22255
Affected products: Fusion Pro, VMware Cloud Foundation, VMware ESXi, VMware Fusion, VMware Workstation, Workstation Pro, vSphere
Suricata
ET EXPLOIT Xiongmai/HiSilicon DVR - OpenTelnet Inbound - Possilbe CVE-2020-22253 Attempt
suricata·2022-12-02·CVSS 9.8
CVE-2020-22253 [CRITICAL] ET EXPLOIT Xiongmai/HiSilicon DVR - OpenTelnet Inbound - Possilbe CVE-2020-22253 Attempt
ET EXPLOIT Xiongmai/HiSilicon DVR - OpenTelnet Inbound - Possilbe CVE-2020-22253 Attempt
Rule: alert tcp-pkt any any -> $HOME_NET 9530 (msg:"ET EXPLOIT Xiongmai/HiSilicon DVR - OpenTelnet Inbound - Possilbe CVE-2020-22253 Attempt"; flow:established,to_server; flowbits:set,ET.CVE-2020-22253; flowbits:noalert; stream_size:server,<,5; dsize:20; content:"|13|OpenTelnet:OpenOnce"; reference:url,habr.com/en/post/486856/; reference:url,vulncheck.com/blog/xiongmai-iot-exploitation; reference:url,github.com/tothi/hs-dvr-telnet; reference:cve,2020-22253; classtype:attempted-recon; sid:2041646; rev:2; metadata:attack_target IoT, created_at 2022_12_02, cve CVE_2020_22253, deployment Perimeter, confidence High, signature_severity Major, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2024_03
No public exploits indexed.
Fortinet
Ransomware Roundup – Shinra and Limpopo Ransomware | FortiGuard Labs
blogs_fortinet·2024-06-14
Ransomware Roundup – Shinra and Limpopo Ransomware | FortiGuard Labs
FORTIGUARD LABS THREAT RESEARCH
Ransomware Roundup – Shinra and Limpopo Ransomware
By Shunichi Imano and Fred Gutierrez | June 14, 2024
FortiGuard Labs gathers data on ransomware variants of interest that have been gaining traction within our datasets and the OSINT community. The Ransomware Roundup report aims to provide readers with brief insights into the evolving ransomware landscape and the Fortinet solutions that protect against those variants.
This edition of the Ransomware Roundup covers the Shinra and Limpopo ransomware.
Affected platforms: Microsoft Windows, VMWare ESXi
Impacted parties: Microsoft Windows and VMWare ESXi Users
Impact: Encrypts victims' files and demands ransom for file decryption
Severity level: High
Shinra Ransomware Overview
The Shinra ransomware was first
Bleepingcomputer
VMware fixes critical sandbox escape flaws in ESXi, Workstation, and Fusion
blogs_bleepingcomputer·2024-03-06·CVSS 9.3
[CRITICAL] VMware fixes critical sandbox escape flaws in ESXi, Workstation, and Fusion
## VMware fixes critical sandbox escape flaws in ESXi, Workstation, and Fusion
## Bill Toulas
VMware released security updates to fix critical sandbox escape vulnerabilities in VMware ESXi, Workstation, Fusion, and Cloud Foundation products, allowing attackers to escape virtual machines and access the host operating system.
These types of flaws are critical as they could permit attackers to gain unauthorized access to the host system where a hypervisor is installed or access other virtual machines running on the same host, breaching their isolation.
The advisory outlines four vulnerabilities , tracked as CVE-2024-22252, CVE-2024-22253, CVE-2024-22254, and CVE-2024-22255, with CVSS v3 scores ranging from 7.1 to 9.3, but all with a critical severity rating.
The four flaws can be summari
2024-03-05
Published
Exploited in the wild