QID 216281

Date Published: 2022-02-21

QID 216281: VMware ESXi 6.5 Patch Release ESXi650-202202401-SG Missing (VMSA-2022-0004)

VMware ESXi is an enterprise-level computer virtualization product.

Affected Versions:
VMware ESXi 6.5 prior to build 19092475

QID Detection Logic (Unauthenticated):
This QID checks for vulnerable versions of VMware ESXi with build version using web service present on the target.

A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host.

  • CVSS V3 rated as High - 6.7 severity.
  • CVSS V2 rated as Medium - 4.6 severity.
  • Solution
    VMware has released patch for VMware ESXi 6.5, visit VMware ESXi 6.5 Patch Release ESXi650-202202401-SG. Refer to VMware advisory VMSA-2022-0004 for more information.

    CVEs related to QID 216281

    Software Advisories
    Advisory ID Software Component Link
    VMSA-2022-0004 URL Logo docs.vmware.com/en/VMware-vSphere/6.5/rn/esxi650-202202001.html