QID 216310

Date Published: 2023-03-30

QID 216310: VMware ESXi 7.0 Patch Release ESXi70U3si-20841705 Missing (VMSA-2022-0030)

VMware ESXi is an enterprise level computer virtualization product.

Affected Versions:
VMware ESXi 7.0.x prior build 20841705

QID Detection Logic (Unauthenticated):
This QID checks for vulnerable versions of VMware ESXi with build version using web service present on target.

Authenticated:
This QID checks whether workaround is applied. If Workaround is applied,QID will not flag.

A malicious actor with local access to ESXi may exploit this issue to corrupt memory leading to an escape of the ESXi sandbox.

  • CVSS V3 rated as Medium - 3.3 severity.
  • CVSS V2 rated as Low - 2.1 severity.
  • Solution
    Vendor has released patch addressing the vulnerability, for more information please refer to VMSA-2022-0030

    CVEs related to QID 216310

    Software Advisories
    Advisory ID Software Component Link
    VMSA-2022-0030 URL Logo www.vmware.com/security/advisories/VMSA-2022-0030.html