QID 377839

Date Published: 2022-12-16

QID 377839: VMware Fusion Heap Out-Of-Bounds Write Vulnerability (VMSA-2022-0033)

VMware Fusion 12.x contain a heap out of bounds write vulnerability in the USB 2.0 controller (EHCI).

Affected Versions:
VMware Fusion 12.x prior to 12.2.5

QID Detection Logic (Authenticated):
This QID checks for vulnerable versions of VMware Fusion.

Note: QID is kept potential due to the workaround.

A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host. In VMware Workstation and Fusion, this may lead to code execution on the machine where Workstation or Fusion is installed.

  • CVSS V3 rated as Critical - 8.2 severity.
  • CVSS V2 rated as High - 7.2 severity.
  • Solution
    Vendor has released patch addressing the vulnerability, for more information please refer to VMSA-2022-0033

    Workaround:
    Please refer to KB79712 to remove USB controller on VMware Fusion.

    CVEs related to QID 377839

    Software Advisories
    Advisory ID Software Component Link
    VMSA-2022-0033 URL Logo www.vmware.com/security/advisories/VMSA-2022-0033.html