CVE-2022-31696

Severity CVSS v4.0:
Pending analysis
Type:
CWE-787 Out-of-bounds Write
Publication date:
13/12/2022
Last modified:
22/04/2025

Description

VMware ESXi contains a memory corruption vulnerability that exists in the way it handles a network socket. A malicious actor with local access to ESXi may exploit this issue to corrupt memory leading to an escape of the ESXi sandbox.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:vmware:cloud_foundation:*:*:*:*:*:*:*:* 3.0 (including) 3.10 (excluding)
cpe:2.3:a:vmware:cloud_foundation:*:*:*:*:*:*:*:* 4.0 (including) 4.3.11 (excluding)
cpe:2.3:a:vmware:cloud_foundation:3.10:-:*:*:*:*:*:*
cpe:2.3:a:vmware:cloud_foundation:3.11:-:*:*:*:*:*:*
cpe:2.3:a:vmware:cloud_foundation:4.3.11:*:*:*:*:*:*:*
cpe:2.3:a:vmware:cloud_foundation:4.4:*:*:*:*:*:*:*
cpe:2.3:a:vmware:cloud_foundation:4.4.1:*:*:*:*:*:*:*
cpe:2.3:a:vmware:cloud_foundation:4.4.1.1:*:*:*:*:*:*:*
cpe:2.3:a:vmware:cloud_foundation:4.5:*:*:*:*:*:*:*
cpe:2.3:o:vmware:esxi:6.5:-:*:*:*:*:*:*
cpe:2.3:o:vmware:esxi:6.5:650-201701001:*:*:*:*:*:*
cpe:2.3:o:vmware:esxi:6.5:650-201703001:*:*:*:*:*:*
cpe:2.3:o:vmware:esxi:6.5:650-201703002:*:*:*:*:*:*
cpe:2.3:o:vmware:esxi:6.5:650-201704001:*:*:*:*:*:*
cpe:2.3:o:vmware:esxi:6.5:650-201707101:*:*:*:*:*:*