QID 377837

Date Published: 2022-12-15

QID 377837: VMware Workstation Heap Out-Of-Bounds Write Vulnerability (VMSA-2022-0033)

VMware Workstation 16.x contain a heap out of bounds write vulnerability in the USB 2.0 controller (EHCI).

Affected Versions:
VMware Workstation 16.x prior to 16.2.5

QID Detection Logic (Authenticated):
This QID checks for vulnerable versions of VMware Workstation.

Note: QID is kept potential due to the workaround.

A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host. In VMware Workstation and Fusion, this may lead to code execution on the machine where Workstation or Fusion is installed.

  • CVSS V3 rated as Critical - 8.2 severity.
  • CVSS V2 rated as High - 7.2 severity.
  • Solution
    Vendor has released patch addressing the vulnerability, for more information please refer to VMSA-2022-0033

    Workaround:
    Please refer to KB79712 to remove USB controller on VMware Workstation.

    CVEs related to QID 377837

    Software Advisories
    Advisory ID Software Component Link
    VMSA-2022-0033 URL Logo www.vmware.com/security/advisories/VMSA-2022-0033.html