Description
VMware ESXi, Workstation, and Fusion contain a heap out-of-bounds write vulnerability in the USB 2.0 controller (EHCI). A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host. On ESXi, the exploitation is contained within the VMX sandbox whereas, on Workstation and Fusion, this may lead to code execution on the machine where Workstation or Fusion is installed.
Exploits (1)
References (1)
Core 1
Core References
Vendor Advisory
https://www.vmware.com/security/advisories/VMSA-2022-0033.html
Scores
CVSS v3
8.2
EPSS
0.0246
EPSS Percentile
85.4%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-787
Status
published
Products (4)
vmware/esxi
7.0 (18 CPE variants)
vmware/esxi
8.0
vmware/fusion
12.0.0 - 12.2.5
vmware/workstation
16.0.0 - 16.2.5
Published
Dec 14, 2022
Tracked Since
Feb 18, 2026