QID 216278

Date Published: 2022-01-12

QID 216278: VMware ESXi 6.5 Patch Release ESXi650-202110101-SG Missing (VMSA-2022-0001)

VMware ESXi is an enterprise-level computer virtualization product.

The CD-ROM device emulation in VMware Workstation, Fusion, and ESXi has a heap-overflow vulnerability.

Affected Versions:
VMware ESXi 6.5 prior to build 18678235

QID Detection Logic (Unauthenticated):
This QID checks for vulnerable versions of VMware ESXi with build version using web service present on the target.

A malicious actor with normal user privilege access to a virtual machine can cause heap-overflow vulnerability via the CD-ROM device emulation.

  • CVSS V3 rated as High - 7.8 severity.
  • CVSS V2 rated as High - 6.9 severity.
  • Solution
    VMware has released patch for VMware ESXi 6.5 , visit VMware ESXi 6.5 , Patch Release ESXi650-202110101-SG
    Refer to VMware advisory VMSA-2022-0001 for more information.

    CVEs related to QID 216278

    Software Advisories
    Advisory ID Software Component Link
    VMware ESXi 6.5 ESXi650-202110101-SG URL Logo docs.vmware.com/en/VMware-vSphere/6.5/rn/esxi650-202110001.html#esxi650-202110101-sg-resolved