880
VMScore

CVE-2021-22045

CVSSv4: NA | CVSSv3: 7.8 | CVSSv2: 6.9 | VMScore: 880 | EPSS: 0.04837 | KEV: Not Included
Published: 04/01/2022 Updated: 21/11/2024

Vulnerability Summary

Heap-Overflow Exploit in VMware CD-ROM Emulation Leads to RCE

VMware ESXi (versions 7.0, 6.7 before ESXi670-202111101-SG, and 6.5 before ESXi650-202110101-SG), VMware Workstation (version 16.2.0), and VMware Fusion (version 12.2.0) have a heap-overflow vulnerability in the CD-ROM device emulation. A malicious actor who can access a virtual machine with CD-ROM device emulation could exploit this vulnerability, along with other issues, to run code on the hypervisor from the virtual machine.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

vmware cloud foundation

vmware workstation

vmware fusion

vmware esxi 6.5

vmware esxi 6.7

vmware esxi 7.0