NA

CVE-2024-22269

Published: 14/05/2024 Updated: 14/05/2024

Vulnerability Summary

VMware Workstation and Fusion contain an information disclosure vulnerability in the vbluetooth device. A malicious actor with local administrative privileges on a virtual machine may be able to read privileged information contained in hypervisor memory from a virtual machine.

Recent Articles

VMware fixes three zero-day bugs exploited at Pwn2Own 2024
BleepingComputer • Sergiu Gatlan • 14 May 2024

VMware fixes three zero-day bugs exploited at Pwn2Own 2024 By Sergiu Gatlan May 14, 2024 10:48 AM 0 VMware fixed four security vulnerabilities in the Workstation and Fusion desktop hypervisors, including three zero-days exploited during the Pwn2Own Vancouver 2024 hacking contest. The most severe flaw patched today is CVE-2024-22267, a use-after-free flaw in the vbluetooth device demoed by the STAR Labs SG and Theori teams. "A malicious actor with local administrative privileges on a virtual mach...

Microsoft fixes a bug abused in QakBot attacks plus a second under exploit
The Register

Topics Security Off-Prem On-Prem Software Offbeat Special Features Vendor Voice Vendor Voice Resources Plus: Google Chrome, Apple bugs also exploited in the wild

Happy May Patch Tuesday. We've got a lot of vendors joining this month's patchapalooza, which includes a handful of bugs that have been exploited — either in the wild or at Pwn2Own — and now fixed by Microsoft, Apple, Google and VMware. Starting with Microsoft: Redmond disclosed and fixed 60 Windows CVEs today including two listed as publicly known and exploited prior to the patch being issued. The first one is an elevation of privilege bug in Windows DWM core library, tracked as CVE-2024-30...