QID 216309
Date Published: 2023-03-30
QID 216309: VMware ESXi 6.7 Patch Release ESXi670-202210101-SG Missing (VMSA-2022-0030)
VMware ESXi is an enterprise level computer virtualization product.
Affected Versions:
VMware ESXi 6.7.x prior build 19997733
QID Detection Logic (Unauthenticated):
This QID checks for vulnerable versions of VMware ESXi with build version using web service present on target.
Authenticated:
This QID checks whether workaround is applied. If Workaround is applied,QID will not flag.
A malicious actor with local access to ESXi may exploit this issue to corrupt memory leading to an escape of the ESXi sandbox.
Solution
Vendor has released patch addressing the vulnerability, for more information please refer to VMSA-2022-0030
Vendor References
- VMSA-2022-0030 -
www.vmware.com/security/advisories/VMSA-2022-0030.html
CVEs related to QID 216309
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| VMSA-2022-0030 |
|