Vulnerability Description
VMware ESXi, Workstation, and Fusion contain a double-fetch vulnerability in the UHCI USB controller. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Vmware | Cloud Foundation | >= 3.0, < 3.11 |
| Vmware | Fusion | >= 12.0.0, < 12.2.1 |
| Vmware | Workstation | >= 16.0.0, < 16.2.1 |
| Vmware | Esxi | 6.5 |
References
- https://www.vmware.com/security/advisories/VMSA-2022-0004.htmlPatchVendor Advisory
- https://www.vmware.com/security/advisories/VMSA-2022-0004.htmlPatchVendor Advisory
FAQ
What is CVE-2021-22041?
CVE-2021-22041 is a vulnerability with a CVSS score of 6.7 (MEDIUM). VMware ESXi, Workstation, and Fusion contain a double-fetch vulnerability in the UHCI USB controller. A malicious actor with local administrative privileges on a virtual machine may exploit this issue...
How severe is CVE-2021-22041?
CVE-2021-22041 has been rated MEDIUM with a CVSS base score of 6.7/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-22041?
Check the references section above for vendor advisories and patch information. Affected products include: Vmware Cloud Foundation, Vmware Fusion, Vmware Workstation, Vmware Esxi.