mirror of
https://github.com/0xMarcio/cve.git
synced 2026-05-27 02:02:23 +02:00
19 lines
1.3 KiB
Markdown
19 lines
1.3 KiB
Markdown
### [CVE-2021-22040](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-22040)
|
|

|
|
%2C%20Workstation%20(16.x%20before%2016.2.1)%2C%20Fusion%20(12.x%20before%2012.2.1)%20and%20VMware%20Cloud%20Foundation%20(4.x%20before%204.4%20and%203.x%20before%203.11)%20&color=brightgreen)
|
|

|
|
|
|
### Description
|
|
|
|
VMware ESXi, Workstation, and Fusion contain a use-after-free vulnerability in the XHCI USB controller. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host.
|
|
|
|
### POC
|
|
|
|
#### Reference
|
|
No PoCs from references.
|
|
|
|
#### Github
|
|
- https://github.com/ARPSyndicate/cvemon
|
|
- https://github.com/EGI-Federation/SVG-advisories
|
|
|