cbcvebase.
CVE-2024-22254
published 2024-03-05

CVE-2024-22254: VMware ESXi contains an out-of-bounds write vulnerability. A malicious actor with privileges within the VMX process may trigger an out-of-bounds write leading…

PriorityP183high8.2CVSS 3.1
AVLACLPRHUINSCCHIHAH
ITWVulnCheck KEVRansomware
Exploited in the wild
EPSS
0.50%
39.6th percentile
VMware ESXi contains an out-of-bounds write vulnerability. A malicious actor with privileges within the VMX process may trigger an out-of-bounds write leading to an escape of the sandbox.

Affected

4 ranges
VendorProductVersion rangeFixed in
vmwarecloud_foundation4.0 – 5.0
vmwareesxi
vmwareesxi
vmwareesxi

Detection & IOCsextracted from sources · hover to see the quote

  • CVE-2024-22254 is an out-of-bounds write in the VMX process on VMware ESXi; monitor for unexpected memory writes or crashes originating from the VMX process, which may indicate sandbox escape attempts.
  • Exploitation of CVE-2024-22254 requires the attacker to already have privileges within the VMX process; focus detection on privilege escalation paths leading to VMX process access on ESXi hosts.
  • ·VMware has made security fixes available for older ESXi versions (6.7U3u, 6.5U3v) and VCF 3.x due to severity; ensure legacy deployments are also patched.
  • ·As of the advisory publication, no active exploitation of CVE-2024-22254 had been observed or reported; however, the exploitation status may change and admins should monitor the VMSA mailing list.

CVSS provenance

nvdv3.18.2HIGHCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
vulncheck7.9HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.