CVE-2024-22255
published 2024-03-05CVE-2024-22255: VMware ESXi, Workstation, and Fusion contain an information disclosure vulnerability in the UHCI USB controller. A malicious actor with administrative access…
PriorityP185high7.1CVSS 3.1
AVLACLPRNUINSCCHINAN
ITWVulnCheck KEVRansomware
Exploited in the wild
EPSS
2.31%
81.5th percentile
VMware ESXi, Workstation, and Fusion contain an information disclosure vulnerability in the UHCI USB controller. A malicious actor with administrative access to a virtual machine may be able to exploit this issue to leak memory from the vmx process.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| vmware | cloud_foundation | 4.0 – 5.0 | — |
| vmware | esxi | — | — |
| vmware | esxi | — | — |
| vmware | esxi | — | — |
| vmware | fusion | >= 13.0.0 < 13.5.1 | 13.5.1 |
| vmware | workstation | >= 17.0.0 < 17.5.1 | 17.5.1 |
Detection & IOCsextracted from sources · hover to see the quote
- →CVE-2024-22255 is an information disclosure vulnerability in the UHCI USB controller of VMware ESXi, Workstation, and Fusion; monitor for administrative-level VM processes attempting to read or leak memory from the vmx process, particularly via UHCI USB controller interactions. ↗
- →Exploitation requires local administrative privileges on the virtual machine; alert on unexpected administrative access to VMs in conjunction with UHCI USB controller activity in the vmx process. ↗
- ·Affected products span multiple VMware product lines and versions including ESXi (including older 6.7U3u and 6.5U3v), Workstation, Fusion, and VMware Cloud Foundation; ensure patch coverage across all deployed versions. ↗
- ·As of the advisory publication, no active exploitation of CVE-2024-22255 had been observed or reported; however, monitoring is advised as status may change. ↗
CVSS provenance
nvdv3.17.1HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
vulncheck7.1HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-3hfr-246f-6fxv: VMware ESXi, Workstation, and Fusion contain an information disclosure vulnerability in the UHCI USB controller
ghsa_unreviewed·2024-03-05
CVE-2024-22255 [HIGH] CWE-770 GHSA-3hfr-246f-6fxv: VMware ESXi, Workstation, and Fusion contain an information disclosure vulnerability in the UHCI USB controller
VMware ESXi, Workstation, and Fusion contain an information disclosure vulnerability in the UHCI USB controller. A malicious actor with administrative access to a virtual machine may be able to exploit this issue to leak memory from the vmx process.
VulnCheck
VMware ESXi, Workstation, and Fusion UHCI USB Controller Vulnerability
vulncheck·2024·CVSS 7.1
CVE-2024-22255 [HIGH] VMware ESXi, Workstation, and Fusion UHCI USB Controller Vulnerability
VMware ESXi, Workstation, and Fusion UHCI USB Controller Vulnerability
VMware ESXi, Workstation, and Fusion contain an information disclosure vulnerability in the UHCI USB controller. A malicious actor with administrative access to a virtual machine may be able to exploit this issue to leak memory from the vmx process.
Affected: VMware ESXi, Workstation, and Fusion
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Known Ransomware Campaign Use: Known
Exploitation References: https://medium.com/s2wblog/ransomware-landscape-in-h1-2024-statistics-and-key-issues-b7502d9f4068
VMware
VMware ESXi, Workstation, and Fusion updates address multiple security vulnerabilities (CVE-2024-22252, CVE-2024-22253, CVE-2024-22254, CVE-2024-22255)
vendor_vmware·2024-03-05·CVSS 9.3
CVE-2024-22252 [CRITICAL] VMware ESXi, Workstation, and Fusion updates address multiple security vulnerabilities (CVE-2024-22252, CVE-2024-22253, CVE-2024-22254, CVE-2024-22255)
VMSA-2024-0006: VMware ESXi, Workstation, and Fusion updates address multiple security vulnerabilities (CVE-2024-22252, CVE-2024-22253, CVE-2024-22254, CVE-2024-22255)
VMware ESXi, Workstation, and Fusion contain a use-after-free vulnerability in the XHCI USB controller. VMware has evaluated the severity of this issue to be in the Critical severity range with a maximum CVSSv3 base score of 9.3 for Workstation/Fusion and in the Important severity range with a maximum CVSSv3 base score of 8.4 for ESXi.
CVEs: CVE-2024-22252, CVE-2024-22253, CVE-2024-22254, CVE-2024-22255
Affected products: Fusion Pro, VMware Cloud Foundation, VMware ESXi, VMware Fusion, VMware Workstation, Workstation Pro, vSphere
No detection rules found.
No public exploits indexed.
Checkpoint
11th March – Threat Intelligence Report
blogs_checkpoint·2024-03-11·CVSS 8.2
CVE-2023-46805 [HIGH] 11th March – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 11th March – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 11th March, please download our Threat_Intelligence Bulletin .
TOP ATTACKS AND BREACHES
Cybersecurity and Infrastructure Security Agency (CISA) has taken offline two systems following a breach that occurred as a result of the recent vulnerabilities exploitation in Ivanti products. The affected systems potentially include the Infrastructure Protection Gateway and the Chemical Security Assessment Tool, holding sen
Bleepingcomputer
VMware fixes critical sandbox escape flaws in ESXi, Workstation, and Fusion
blogs_bleepingcomputer·2024-03-06·CVSS 9.3
[CRITICAL] VMware fixes critical sandbox escape flaws in ESXi, Workstation, and Fusion
## VMware fixes critical sandbox escape flaws in ESXi, Workstation, and Fusion
## Bill Toulas
VMware released security updates to fix critical sandbox escape vulnerabilities in VMware ESXi, Workstation, Fusion, and Cloud Foundation products, allowing attackers to escape virtual machines and access the host operating system.
These types of flaws are critical as they could permit attackers to gain unauthorized access to the host system where a hypervisor is installed or access other virtual machines running on the same host, breaching their isolation.
The advisory outlines four vulnerabilities , tracked as CVE-2024-22252, CVE-2024-22253, CVE-2024-22254, and CVE-2024-22255, with CVSS v3 scores ranging from 7.1 to 9.3, but all with a critical severity rating.
The four flaws can be summari
2024-03-05
Published
Exploited in the wild