Description
VMware ESX, Workstation, and Fusion contain an out-of-bounds read vulnerability. A malicious actor with VM deployment privileges could trigger an out-of-bounds read, potentially leading to information disclosure or more likely a Denial-of-Service (DoS) condition of the host process. On Workstation and Fusion, the impact of this vulnerability is restricted to information disclosure.
CVSS breakdown
CVSS 3.1
Attack Vector
Network
Attack Complexity
Low
Privileges Required
High
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
None
Availability
Low
Affected products
- VMware / Cloud Foundation9.1.x.x – 9.1.x.x
- VMware / Cloud Foundation9.0.x.x – 9.0.x.x
- VMware / Cloud Foundation5.x – 5.2.3
- VMware / ESX9.0.x.x – ESXi-9.0.2.0100-25595025
- VMware / ESX9.1.x.x – ESXi-9.1.0.0-25370933
- VMware / ESX8.0 – ESXi80U3i-25205845
- VMware / Fusion25H2 – 26H1
- VMware / Telco Cloud Platform5.0.x – 5.0.x
- VMware / Telco Cloud Platform5.1.x – 5.1.x
- VMware / vSphere Foundation9.1.x.x – 9.1.x.x
- VMware / vSphere Foundation9.0.x.x – 9.0.x.x
- VMware / Workstation25H2 – 26H1
Updated 20m ago · 8 sources