CVE-2024-37085
- EPSS 65.24%
- Published 25.06.2024 15:15:12
- Last modified 20.12.2024 16:52:43
VMware ESXi contains an authentication bypass vulnerability. A malicious actor with sufficient Active Directory (AD) permissions can gain full access to an ESXi host that was previously configured to use AD for user management https://blogs.vmware.c...
CVE-2024-37086
- EPSS 0.07%
- Published 25.06.2024 15:15:12
- Last modified 27.06.2025 13:39:14
VMware ESXi contains an out-of-bounds read vulnerability. A malicious actor with local administrative privileges on a virtual machine with an existing snapshot may trigger an out-of-bounds read leading to a denial-of-service condition of the host.
CVE-2024-22273
- EPSS 0.22%
- Published 21.05.2024 18:15:08
- Last modified 26.03.2025 16:15:19
The storage controllers on VMware ESXi, Workstation, and Fusion have out-of-bounds read/write vulnerability. A malicious actor with access to a virtual machine with storage controllers enabled may exploit this issue to create a denial of service cond...
CVE-2024-22254
- EPSS 0.41%
- Published 05.03.2024 18:15:48
- Last modified 07.05.2025 15:37:28
VMware ESXi contains an out-of-bounds write vulnerability. A malicious actor with privileges within the VMX process may trigger an out-of-bounds write leading to an escape of the sandbox.
CVE-2024-22255
- EPSS 4.35%
- Published 05.03.2024 18:15:48
- Last modified 07.05.2025 15:37:25
VMware ESXi, Workstation, and Fusion contain an information disclosure vulnerability in the UHCI USB controller. A malicious actor with administrative access to a virtual machine may be able to exploit this issue to leak memory from the vmx process. ...
CVE-2024-22252
- EPSS 0.35%
- Published 05.03.2024 18:15:47
- Last modified 27.03.2025 20:15:21
VMware ESXi, Workstation, and Fusion contain a use-after-free vulnerability in the XHCI USB controller. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX pr...
CVE-2024-22253
- EPSS 0.08%
- Published 05.03.2024 18:15:47
- Last modified 07.05.2025 15:35:46
VMware ESXi, Workstation, and Fusion contain a use-after-free vulnerability in the UHCI USB controller. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX pr...
CVE-2023-29552
- EPSS 93.54%
- Published 25.04.2023 16:15:09
- Last modified 27.03.2025 14:08:54
The Service Location Protocol (SLP, RFC 2608) allows an unauthenticated, remote attacker to register arbitrary services. This could allow the attacker to use spoofed UDP traffic to conduct a denial-of-service attack with a significant amplification f...
CVE-2022-31705
- EPSS 0.96%
- Published 14.12.2022 19:15:13
- Last modified 21.11.2024 07:05:10
VMware ESXi, Workstation, and Fusion contain a heap out-of-bounds write vulnerability in the USB 2.0 controller (EHCI). A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual ...
CVE-2022-31696
- EPSS 0.4%
- Published 13.12.2022 16:15:19
- Last modified 22.04.2025 16:15:29
VMware ESXi contains a memory corruption vulnerability that exists in the way it handles a network socket. A malicious actor with local access to ESXi may exploit this issue to corrupt memory leading to an escape of the ESXi sandbox.