Get the latest tech news
VMware sandbox escape bugs are so critical, patches are released for end-of-life products | VMware ESXi, Workstation, Fusion, and Cloud Foundation all affected
VMware ESXi, Workstation, Fusion, and Cloud Foundation all affected.
VMware officials said that the prospect of a hypervisor escape warranted an immediate response under the company’s IT Infrastructure Library, a process usually abbreviated as ITIL. “In ITIL terms, this situation qualifies as an emergency change, necessitating prompt action from your organization,” the officials wrote in a post. ProductVersionRunning OnCVE IdentifierCVSSv3SeverityFixed Version [1]WorkaroundsAdditional DocumentationESXi8.0AnyCVE-2024-22252, CVE-2024-22253, CVE-2024-22254, CVE-2024-222558.4, 8.4, 7.9, 7.1criticalESXi80U2sb-23305545KB96682FAQESXi8.0 [2]AnyCVE-2024-22252, CVE-2024-22253, CVE-2024-22254, CVE-2024-222558.4, 8.4, 7.9, 7.1criticalESXi80U1d-23299997KB96682FAQESXi7.0AnyCVE-2024-22252, CVE-2024-22253, CVE-2024-22254, CVE-2024-222558.4, 8.4, 7.9, 7.1criticalESXi70U3p-23307199KB96682FAQWorkstation17.xAnyCVE-2024-22252, CVE-2024-22253, CVE-2024-222559.3, 9.3, 7.1critical17.5.1KB96682None.Fusion13.xMacOSCVE-2024-22252, CVE-2024-22253, CVE-2024-222559.3, 9.3, 7.1critical13.5.1KB96682NoneThree of the vulnerabilities affect the USB controller the products use to support peripheral devices such as keyboards and mice.
Or read this on r/technology