QID 379460
Date Published: 2024-03-07
QID 379460: VMware Workstation and VMware Fusion Multiple Vulnerabilities (VMSA-2024-0006)
VMware Workstation, Fusion is a hosted hypervisor that runs on x64 versions of Windows and Linux operating systems.
Affected Versions:
VMware Workstation Pro 17.x prior to 17.5.1
VMware Workstation Player 17.x prior to 17.5.1
VMware Fusion prior to 13.x prior to 13.5.1
QID Detection Logic (Authenticated) - Windows:
This QID checks for registry key "HKLM\SOFTWARE\VMware, Inc.\VMware Workstation" and value "InstallPath" to scan the/ check for file "vmware.exe". Then checks the version for this exe file on Windows Operating Systems
QID Detection Logic: (Authenticated) - Linux:
This QID executes the command "vmware-installer -l|grep vmware-workstation|awk '{print }'" and checks for the VMware Workstation version on Linux Operating Systems
QID Detection Logic: (Authenticated) - MacOS:
This QID checks installed apps on MacOs for the app "VMware Fusion.app". If the app is found, the QID checks for the VMware Fusion version on MacOS
Note: We cannot check the workaround mentioned which is hardware change. So QID set as practice.
After successful exploitation this vulnerability, malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host.
Refer to VMware advisory VMSA-2024-0006 for more information.
Workaround:
The workaround is to remove all USB controllers from the Virtual Machine. As a result, USB passthrough functionality will be unavailable.
- VMSA-2024-0006 -
www.vmware.com/security/advisories/VMSA-2024-0006.html
CVEs related to QID 379460
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| VMSA-2024-0006 |
|