CVE-2024-22254
published 2024-03-05CVE-2024-22254: VMware ESXi contains an out-of-bounds write vulnerability. A malicious actor with privileges within the VMX process may trigger an out-of-bounds write leading…
PriorityP183high8.2CVSS 3.1
AVLACLPRHUINSCCHIHAH
ITWVulnCheck KEVRansomware
Exploited in the wild
EPSS
0.50%
39.6th percentile
VMware ESXi contains an out-of-bounds write vulnerability. A malicious actor with privileges within the VMX process may trigger an out-of-bounds write leading to an escape of the sandbox.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| vmware | cloud_foundation | 4.0 – 5.0 | — |
| vmware | esxi | — | — |
| vmware | esxi | — | — |
| vmware | esxi | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →CVE-2024-22254 is an out-of-bounds write in the VMX process on VMware ESXi; monitor for unexpected memory writes or crashes originating from the VMX process, which may indicate sandbox escape attempts. ↗
- →Exploitation of CVE-2024-22254 requires the attacker to already have privileges within the VMX process; focus detection on privilege escalation paths leading to VMX process access on ESXi hosts. ↗
- ·VMware has made security fixes available for older ESXi versions (6.7U3u, 6.5U3v) and VCF 3.x due to severity; ensure legacy deployments are also patched. ↗
- ·As of the advisory publication, no active exploitation of CVE-2024-22254 had been observed or reported; however, the exploitation status may change and admins should monitor the VMSA mailing list. ↗
CVSS provenance
nvdv3.18.2HIGHCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
vulncheck7.9HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-mw76-72hw-4357: VMware ESXi contains an out-of-bounds write vulnerability
ghsa_unreviewed·2024-03-05
CVE-2024-22254 [HIGH] CWE-787 GHSA-mw76-72hw-4357: VMware ESXi contains an out-of-bounds write vulnerability
VMware ESXi contains an out-of-bounds write vulnerability. A malicious actor with privileges within the VMX process may trigger an out-of-bounds write leading to an escape of the sandbox.
VulnCheck
VMware ESXi Out-of-bounds Write Vulnerability
vulncheck·2024·CVSS 7.9
CVE-2024-22254 [HIGH] VMware ESXi Out-of-bounds Write Vulnerability
VMware ESXi Out-of-bounds Write Vulnerability
VMware ESXi contains an out-of-bounds write vulnerability. A malicious actor with privileges within the VMX process may trigger an out-of-bounds write leading to an escape of the sandbox.
Affected: VMware ESXi
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Known Ransomware Campaign Use: Known
Exploitation References: https://medium.com/s2wblog/ransomware-landscape-in-h1-2024-statistics-and-key-issues-b7502d9f4068
VMware
VMware ESXi, Workstation, and Fusion updates address multiple security vulnerabilities (CVE-2024-22252, CVE-2024-22253, CVE-2024-22254, CVE-2024-22255)
vendor_vmware·2024-03-05·CVSS 9.3
CVE-2024-22252 [CRITICAL] VMware ESXi, Workstation, and Fusion updates address multiple security vulnerabilities (CVE-2024-22252, CVE-2024-22253, CVE-2024-22254, CVE-2024-22255)
VMSA-2024-0006: VMware ESXi, Workstation, and Fusion updates address multiple security vulnerabilities (CVE-2024-22252, CVE-2024-22253, CVE-2024-22254, CVE-2024-22255)
VMware ESXi, Workstation, and Fusion contain a use-after-free vulnerability in the XHCI USB controller. VMware has evaluated the severity of this issue to be in the Critical severity range with a maximum CVSSv3 base score of 9.3 for Workstation/Fusion and in the Important severity range with a maximum CVSSv3 base score of 8.4 for ESXi.
CVEs: CVE-2024-22252, CVE-2024-22253, CVE-2024-22254, CVE-2024-22255
Affected products: Fusion Pro, VMware Cloud Foundation, VMware ESXi, VMware Fusion, VMware Workstation, Workstation Pro, vSphere
No detection rules found.
No public exploits indexed.
2024-03-05
Published
Exploited in the wild