Skip to content
May 24, 2025
  • Linkedin
  • Twitter
  • Facebook
  • Youtube

Daily CyberSecurity

Primary Menu
  • Home
  • Cyber Security
  • Cybercriminals
  • Data Leak
  • Linux
  • Malware Attack
  • Open Source Tool
  • Technology
  • Vulnerability
  • Home
  • News
  • Vulnerability
  • CVE-2022-31705: VMware ESXi, Workstation, and Fusion code execution
  • Vulnerability

CVE-2022-31705: VMware ESXi, Workstation, and Fusion code execution

Ddos December 13, 2022 2 min read
CVE-2022-31705

VMware this week shipped security updates for its Workstation, Fusion, and ESXi product lines, warning that a heap out-of-bounds write vulnerability could expose users to code execution attacks.

Tracked as CVE-2022-31705 (CVSS score of 9.3), the security vulnerability exists in the USB 2.0 controller (EHCI) function of Workstation, Fusion, and ESXi. An attacker could exploit this vulnerability to execute arbitrary code on the system. the organizers of GeekPwn 2022 and the security researcher Yuhao Jiang were credited with reporting the bug.

CVE-2022-31705

“A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine’s VMX process running on the host. On ESXi, the exploitation is contained within the VMX sandbox whereas, on Workstation and Fusion, this may lead to code execution on the machine where Workstation or Fusion is installed,” VMWare said in its advisory.

CVE-2022-31705 affects ESXi 7.0, and 8.0 versions, Fusion 12.x, and Workstation 16.x. VMware Cloud Foundation (ESXi) 4.x and 3.x are affected as well.

VMware has addressed the bug with the release of ESXi80a-20842819, ESXi70U3si-20841705, Workstation 16.2.5, and Fusion 12.2.5. Customers are advised to apply the fixes as soon as possible.

Today, VMware also has fixed two security vulnerabilities in VMware Workspace ONE Access and Identity Manager:

  • CVE-2022-31700 (CVSS score: 7.2): Authenticated Remote Code Execution Vulnerability in VMware Workspace ONE Access and Identity Manager
  • CVE-2022-31701 (CVSS score: 5.3): Broken Authentication Vulnerability in VMware Workspace ONE Access and Identity Manager
Rate this post

Found this helpful?

If this article helped you, please share it with others who might benefit.

Tags: CVE-2022-31700 CVE-2022-31701 CVE-2022-31705

Continue Reading

Previous: CVE-2022-27518: Critical 0-day vulnerability in Citrix ADC and Gateway
Next: CVE-2022-31702: Unauthenticated command injection vulnerability in VMware vRNI

Search

💙 Support Us!
We need 50 contributors this month to keep this site running.
19 of 50 supporters this month
☕ Buy Me a Coffee PayPalDonate
Our Websites
  • Penetration Testing Tools
  • The Daily Information Technology
    • About SecurityOnline.info
    • Advertise on SecurityOnline.info
    • Contact

    When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

    • Disclaimer
    • Privacy Policy
    • DMCA NOTICE
    • Linkedin
    • Twitter
    • Facebook
    • Youtube
    Copyright © All rights reserved.
    x