QID 216302

Date Published: 2022-12-16

QID 216302: VMware ESXi 8.0 Patch Release ESXi80a-20842819 Missing (VMSA-2022-0033)

VMware ESXi is an enterprise level computer virtualization product.

Affected Versions:
VMware ESXi 8.0.x prior build 20842819

QID Detection Logic (Unauthenticated):
This QID checks for vulnerable versions of VMware ESXi with build version using web service present on target.

A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host.

  • CVSS V3 rated as Critical - 8.2 severity.
  • CVSS V2 rated as Medium - 4.6 severity.
  • Solution
    Vendor has released patch addressing the vulnerability, for more information please refer to VMSA-2022-0033

    Workaround:
    Please refer to KB87617 to remove USB controller on VMware ESXi.

    CVEs related to QID 216302

    Software Advisories
    Advisory ID Software Component Link
    VMSA-2022-0033 URL Logo www.vmware.com/security/advisories/VMSA-2022-0033.html