cbcvebase.
CVE-2024-22253
published 2024-03-05

CVE-2024-22253: VMware ESXi, Workstation, and Fusion contain a use-after-free vulnerability in the UHCI USB controller. A malicious actor with local administrative privileges…

PriorityP183medium6.7CVSS 3.1
AVLACLPRHUINSUCHIHAH
ITWVulnCheck KEVRansomware
Exploited in the wild
EPSS
0.65%
46.9th percentile
VMware ESXi, Workstation, and Fusion contain a use-after-free vulnerability in the UHCI USB controller. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host. On ESXi, the exploitation is contained within the VMX sandbox whereas, on Workstation and Fusion, this may lead to code execution on the machine where Workstation or Fusion is installed.

Affected

6 ranges
VendorProductVersion rangeFixed in
vmwarecloud_foundation4.0 – 5.0
vmwareesxi
vmwareesxi
vmwareesxi
vmwarefusion>= 13.0.0 < 13.5.113.5.1
vmwareworkstation>= 17.0.0 < 17.5.117.5.1

Detection & IOCsextracted from sources · hover to see the quote

hash31eec61ed6866e0b4b3d6b26a3a7d65fed040df61062dd468a1f5be8cc709de7
registryHKCU\Control Panel\Desktop\Wallpaper
registryHKLM\Software\Microsoft\Windows\CurrentVersion\OEMInformation
urlhxxps://getsession[.]org/
  • Detect Shinra ransomware by monitoring wevtutil.exe invocations used to enumerate and clear Windows event logs
  • CVE-2024-22253 targets the UHCI USB controller; detect exploitation attempts by monitoring VMX process anomalies or unexpected code execution from VMX sandbox on ESXi hosts
  • Shinra ransomware copies itself to the current user's startup folder as a 32-hex-character named .exe; monitor startup folder for newly created executables matching this pattern
  • ·The Fortinet report notes the CVE numbers in the tweet referencing exploitation may contain a typo ('CVE-20204-22252' and 'CVE-20204-22253'), and exploitation of CVE-2024-22253 by Socotra/Limpopo ransomware is unverified
  • ·VMware had not observed nor received reports of active exploitation of CVE-2024-22253 at time of advisory publication
  • ·CVE-2024-22253 exploitation on ESXi is contained within the VMX sandbox, but on Workstation and Fusion it may lead to full host code execution — detection and response scope differs by platform

CVSS provenance

nvdv3.16.7MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
vulncheck9.3CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.