CVE-2024-22267
published 2024-05-14CVE-2024-22267: VMware Workstation and Fusion contain a use-after-free vulnerability in the vbluetooth device. A malicious actor with local administrative privileges on a…
PriorityP340high8.2CVSS 3.1
AVLACLPRHUINSCCHIHAH
EPSS
0.68%
48.8th percentile
VMware Workstation and Fusion contain a use-after-free vulnerability in the vbluetooth device. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| vmware | fusion | >= 13.0.0 < 13.5.2 | 13.5.2 |
| vmware | workstation | >= 17.0.0 < 17.5.2 | 17.5.2 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Checkpoint
20th May – Threat Intelligence Report
blogs_checkpoint·2024-05-20
CVE-2024-30051 20th May – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 20th May – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 20th May, please download our Threat_Intelligence Bulletin .
TOP ATTACKS AND BREACHES
Australian electronic prescriptions provider MediSecure suffered a significant ransomware attack, leading to widespread disruptions and data breaches. The impact of the attack has been profound, broadly affecting healthcare data broadly in the country.
WebTPA, an American healthcare management and administrative services provide
Bleepingcomputer
VMware fixes three zero-day bugs exploited at Pwn2Own 2024
blogs_bleepingcomputer·2024-05-14·CVSS 9.3
CVE-2024-22267 [CRITICAL] VMware fixes three zero-day bugs exploited at Pwn2Own 2024
## VMware fixes three zero-day bugs exploited at Pwn2Own 2024
## Sergiu Gatlan
VMware fixed four security vulnerabilities in the Workstation and Fusion desktop hypervisors, including three zero-days exploited during the Pwn2Own Vancouver 2024 hacking contest.
The most severe flaw patched today is CVE-2024-22267, a use-after-free flaw in the vbluetooth device demoed by the STAR Labs SG and Theori teams.
"A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host," the company explains in a security advisory published on Tuesday.
VMware also provides a temporary workaround for admins who cannot immediately install today's security updates. This workaround requires them to tur
2024-05-14
Published