V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsProductsVendorsDocs
BDU:2022-07259
BDU
CriticalConfirmedExploit available

Уязвимость контроллера USB 2.0 (EHCI) гипервизоров VMware ESXi, VMware Workstation и VMware Fusion и платформы виртуализации VMware Cloud F…

CVSS
9.3
Critical
EPSS
0.00
p0
Published
2022-01-01
Updated
2022-01-01
Description

Уязвимость контроллера USB 2.0 (EHCI) гипервизоров VMware ESXi, VMware Workstation и VMware Fusion и платформы виртуализации VMware Cloud Foundation связана с возможностью записи за пределами буфера в куче. Эксплуатация уязвимости может позволить нарушителю выполнить произвольный код

Affected products
Broadcom inc. Vmware cloud foundationBroadcom inc. Vmware cloud foundationBroadcom inc. Vmware esxiBroadcom inc. Vmware esxiBroadcom inc. Vmware fusionBroadcom inc. Vmware workstation
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Timeline
2022-01-01
Published
2022-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: L
Local (L)
Attack Complexity
AC: L
Low (L)
Privileges Required
PR: N
None (N)
User Interaction
UI: N
None (N)
Scope
S: C
Changed (C)
Confidentiality Impact
C: H
High (H)
Integrity Impact
I: H
High (H)
Availability Impact
A: H
High (H)
Exploit indicators
EPSS
0.000 · p0
Known exploited (KEV)
No
Known exploits — Сканер-ВС
CVE-2022-31705
github-poc · https://github.com/s0duku/cve-2022-31705
Enterprise
Affected products
ProductVendorStatus
vmware cloud foundationbroadcom inc.Tracked
vmware cloud foundationbroadcom inc.Tracked
vmware esxibroadcom inc.Tracked
vmware esxibroadcom inc.Tracked
vmware fusionbroadcom inc.Tracked
vmware workstationbroadcom inc.Tracked