QID 376228

Date Published: 2022-01-17

QID 376228: VMware Workstation and VMware Fusion Heap Overflow Vulnerability (VMSA-2022-0001)

VMware Workstation, Fusion is a hosted hypervisor that runs on x64 versions of Windows and Linux operating systems.

The CD-ROM device emulation in VMware Workstation, Fusion and ESXi has a heap-overflow vulnerability.

Affected Versions:
VMware Workstation Pro 16.x prior to 16.2.0
VMware Workstation Player 16.x prior to 16.2.0
VMware Fusion prior to 12.x prior to 12.2.0

QID Detection Logic (Unauthenticated):
This QID checks for vulnerable versions of Workstation and Fusion .exe file.

A malicious actor with normal user privilege access to a virtual machine can cause heap-overflow vulnerability via the CD-ROM device emulation.

  • CVSS V3 rated as High - 7.8 severity.
  • CVSS V2 rated as High - 6.9 severity.
  • Solution
    Vmware has released patch for VMware Workstation and VMware Fusion.

    Refer to VMware advisory VMSA-2022-0001 for more information.

    CVEs related to QID 376228

    Software Advisories
    Advisory ID Software Component Link
    VMware Fusion 12.2.0 URL Logo docs.vmware.com/en/VMware-Fusion/12.2.0/rn/VMware-Fusion-1220-Release-Notes.html
    VMware Workstation 16.2.0 URL Logo docs.vmware.com/en/VMware-Workstation-Pro/16.2.0/rn/VMware-Workstation-1620-Pro-Release-Notes.html