VMware Security Updates 13 December 2022

VMware has released security updates to fix a zero-day vulnerability across multiple products.

The addressed vulnerability could allow the attacker with local administrative privileges on a virtual machine to execute code to gain access to the affected products.

Heap out-of-bounds write vulnerability in EHCI controller (CVE-2022-31705)

• CVSS: 9.3

• Attack Vector: Local

• Attack Complexity: low

• Privileges Required: None

• User Interaction: None

• Consequences: Gain Access

Affected Products:

• VMware ESXi

• VMware Workstation Pro / Player (Workstation)

• VMware Fusion Pro / Fusion (Fusion)

• VMware Cloud Foundation

Vulnerabilities
  • CVE-2022-31705
Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

VMware Security Advisory

References