CVE-2024-22269

Severity
6.0MEDIUM
EPSS
0.1%
top 76.93%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 14

Description

VMware Workstation and Fusion contain an information disclosure vulnerability in the vbluetooth device. A malicious actor with local administrative privileges on a virtual machine may be able to read privileged information contained in hypervisor memory from a virtual machine.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:NExploitability: 2.5 | Impact: 4.0

Affected Packages4 packages

CVEListV5vmware_fusion13.x13.5.2
NVDvmware/fusion13.0.013.5.2
CVEListV5vmware_workstation17.x17.5.2
NVDvmware/workstation17.0.017.5.2

🔴Vulnerability Details

2
CVEList
CVE-2024-22269: VMware Workstation and Fusion contain an information disclosure vulnerability in the vbluetooth device2024-05-14
GHSA
GHSA-fv84-h83r-2rc5: VMware Workstation and Fusion contain an information disclosure vulnerability in the vbluetooth device2024-05-14