CVE-2024-10228

LOW

Vagrant VMWare Utility <1.0.23 - Privilege Escalation

Title source: llm
STIX 2.1

Description

The Vagrant VMWare Utility Windows installer targeted a custom location with a non-protected path that could be modified by an unprivileged user, introducing potential for unauthorized file system writes. This vulnerability, CVE-2024-10228, was fixed in Vagrant VMWare Utility 1.0.23

Scores

CVSS v3 3.8
EPSS 0.0004
EPSS Percentile 12.9%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-732
Status published
Products (1)
hashicorp/vagrant_vmware_utility < 1.0.23
Published Oct 29, 2024
Tracked Since Feb 18, 2026