CVE-2024-22267
EUVD-2024-1983114.05.2024, 16:16
VMware Workstation and Fusion contain a use-after-free vulnerability in the vbluetooth device. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| vmware | fusion | 13.0.0 ≤ 𝑥 < 13.5.2 |
| vmware | workstation | 17.0.0 ≤ 𝑥 < 17.5.2 |
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| vmware | vmware_workstation | 17.0 ≤ 𝑥 < 17.5.2 | ADP |
| vmware | fusion | 13.0.0 ≤ 𝑥 < 13.5.2 | ADP |
Common Weakness Enumeration