Vulnerabilities in VMware software expose it to remote execution of code by threat actors due to critical defects.
These are found in different parts of the virtualization platform, management interfaces, and other related tools, making the flaw latent.
This can enable them to gain higher access levels, thereby running malicious codes from afar on computers affected through successful exploitation.
Multiple vulnerabilities were privately reported to VMware recently in VMware ESXi, Workstation, and Fusion.
As a result, VMware patched the critical flaws in ESXi, Workstation, and Fusion after private disclosure. Combining multiple important vulnerabilities escalates severity.
Malware analysis can be fast and simple. Just let us show you the way to:
Here below, we have mentioned all the vulnerabilities:-
Here below, we have mentioned all the products that are impacted:-
The vulnerability (CVE-2024-22252) allows code execution from VM in VMware products.
While the VMware XHCI USB flaw (CVE-2024-22253) is critical for Workstation/Fusion, but important for ESXi.
UHCI USB bug also impacts VMware products as well and enables code execution. Out-of-bounds write flaw (CVE-2024-22254) in ESXi risks VMX sandbox escape.
Memory leak possible via UHCI USB flaw (CVE-2024-22255) across VMware lineup.
Broadcom released critical patches for severe vulnerabilities in ESXi 6.7, 6.5, and VCF 3.x. Additional patches are available for ESXi 8.0 U1.
If not updating to ESXi 8.0 Update 2b, use 8.0 Update 1d for security fixes.
With Perimeter81 malware protection, you can block malware, including Trojans, ransomware, spyware, rootkits, worms, and zero-day exploits. All are incredibly harmful and can wreak havoc on your network.
Stay updated on Cybersecurity news, Whitepapers, and Infographics. Follow us on LinkedIn & Twitter.
VMware has released a critical security advisory, VMSA-2025-0003, addressing multiple vulnerabilities in VMware Aria Operations for…
The Cybersecurity and Infrastructure Security Agency (CISA) has issued a critical advisory regarding multiple vulnerabilities…
Researchers at Palo Alto Networks' Unit 42 have revealed a troubling surge in large language…
Cybereason Security Services has published a comprehensive threat analysis highlighting the resurgence of the Phorpiex…
A critical unauthenticated Remote Code Execution (RCE) vulnerability has been identified in D-Link's DSL-3788 routers,…
Authorities have delivered a major blow to the cybercrime world by dismantling two of the…