8.8
CVE-2022-31696
- EPSS 0.34%
- Veröffentlicht 13.12.2022 16:15:19
- Zuletzt bearbeitet 22.04.2025 16:15:29
- Erkennungen
VMware ESXi contains a memory corruption vulnerability that exists in the way it handles a network socket. A malicious actor with local access to ESXi may exploit this issue to corrupt memory leading to an escape of the ESXi sandbox.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
VMware ≫ Cloud Foundation Version >= 3.0 < 3.10
VMware ≫ Cloud Foundation Version >= 4.0 < 4.3.11
VMware ≫ Cloud Foundation Version 3.10 Update -
VMware ≫ Cloud Foundation Version 3.11 Update -
VMware ≫ Cloud Foundation Version 4.3.11
VMware ≫ Cloud Foundation Version 4.4
VMware ≫ Cloud Foundation Version 4.4.1
VMware ≫ Cloud Foundation Version 4.4.1.1
VMware ≫ Cloud Foundation Version 4.5
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.34% | 0.256 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 8.8 | 2 | 6 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
|
| CISA-ADP | 8.8 | 2 | 6 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
|
CWE-787 Out-of-bounds Write
The product writes data past the end, or before the beginning, of the intended buffer.
https://www.vmware.com/security/advisories/VMSA-2022-0030.html