CVE-2021-22040

Severity CVSS v4.0:
Pending analysis
Type:
CWE-416 Use After Free
Publication date:
16/02/2022
Last modified:
24/02/2022

Description

VMware ESXi, Workstation, and Fusion contain a use-after-free vulnerability in the XHCI USB controller. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:vmware:cloud_foundation:*:*:*:*:*:*:*:* 3.0 (including) 3.11 (excluding)
cpe:2.3:a:vmware:cloud_foundation:*:*:*:*:*:*:*:* 4.0 (including) 4.4 (excluding)
cpe:2.3:a:vmware:fusion:*:*:*:*:*:*:*:* 12.0.0 (including) 12.2.1 (excluding)
cpe:2.3:a:vmware:workstation_player:*:*:*:*:*:*:*:* 16.0.0 (including) 16.2.1 (excluding)
cpe:2.3:a:vmware:workstation_pro:*:*:*:*:*:*:*:* 16.0.0 (including) 16.2.1 (excluding)
cpe:2.3:o:vmware:esxi:6.5:-:*:*:*:*:*:*
cpe:2.3:o:vmware:esxi:6.5:650-202202401:*:*:*:*:*:*
cpe:2.3:o:vmware:esxi:6.7:-:*:*:*:*:*:*
cpe:2.3:o:vmware:esxi:6.7:670-201806001:*:*:*:*:*:*
cpe:2.3:o:vmware:esxi:6.7:670-201807001:*:*:*:*:*:*
cpe:2.3:o:vmware:esxi:6.7:670-201808001:*:*:*:*:*:*
cpe:2.3:o:vmware:esxi:6.7:670-201810001:*:*:*:*:*:*
cpe:2.3:o:vmware:esxi:6.7:670-201810101:*:*:*:*:*:*
cpe:2.3:o:vmware:esxi:6.7:670-201810102:*:*:*:*:*:*
cpe:2.3:o:vmware:esxi:6.7:670-201810103:*:*:*:*:*:*


References to Advisories, Solutions, and Tools