QID 216321
Date Published: 2024-03-08
QID 216321: VMware ESXi 8.0 [2] Patch Release ESXi80U1d-23299997 Missing (VMSA-2024-0006.1)
VMware ESXi is an enterprise level computer virtualization product.
Affected Versions:
VMware ESXi 8.0.x prior build 23299997
QID Detection Logic (Unauthenticated):
This QID checks for vulnerable versions of VMware ESXi with build version using web service present on target.
NOTE: This QID is marked as Practice as we there is workaround which user interaction.
A malicious actor with local access to ESXi may exploit this issue to corrupt memory leading to an escape of the ESXi sandbox.
Solution
Vendor has released patch addressing the vulnerability, for more information please refer to VMSA-2024-0006
Workaround:
How to remove USB controllers from a Virtual Machine (96682)
https://kb.vmware.com/s/article/96682
Vendor References
- VMSA-2024-0006.1 -
www.vmware.com/security/advisories/VMSA-2024-0006.html
CVEs related to QID 216321
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| VMSA-2024-0006.1 |
|