Vulnerability Description
The Vagrant VMWare Utility Windows installer targeted a custom location with a non-protected path that could be modified by an unprivileged user, introducing potential for unauthorized file system writes. This vulnerability, CVE-2024-10228, was fixed in Vagrant VMWare Utility 1.0.23
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Hashicorp | Vagrant Vmware Utility | < 1.0.23 |
Related Weaknesses (CWE)
References
FAQ
What is CVE-2024-10228?
CVE-2024-10228 is a vulnerability with a CVSS score of 3.8 (LOW). The Vagrant VMWare Utility Windows installer targeted a custom location with a non-protected path that could be modified by an unprivileged user, introducing potential for unauthorized file system wri...
How severe is CVE-2024-10228?
CVE-2024-10228 has been rated LOW with a CVSS base score of 3.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-10228?
Check the references section above for vendor advisories and patch information. Affected products include: Hashicorp Vagrant Vmware Utility.