SecPod

Learn Search

Search across all Learn content

← Back to Security Research
VMWare Catches New Critical ESXi Sandbox Escape Bugs

VMWare Catches New Critical ESXi Sandbox Escape Bugs

VMWare’s latest advisory reveals four new vulnerabilities affecting its ESXi, Workstation, Fusion, and Cloud Foundation products. Each vulnerability has been patched, with support even being extended for end-of-life products – an unusual but vital decision for this unprecedented situation.

Mar 5, 2024By Meghana Raatni2 min read

VMWare’s latest advisory reveals four new vulnerabilities affecting its ESXi, Workstation, Fusion, and Cloud Foundation products. Each vulnerability has been patched, with support even being extended for end-of-life products – an unusual but vital decision for this unprecedented situation.

Solutions such as vulnerability management software and patch management software will detect and automatically fix vulnerabilities. You can read more about this in the final section of the blog. For now, let’s take a look at the technical details of the aforementioned bugs.

Technical Details

CVE-2024-22252andCVE-2024-22253: Use-after-free vulnerabilities, both rated critical at 9.3, in the XHCI and UHCI USB controllers respectively. An attacker with local administrative access on a virtual machine can execute code as the virtual machine’s VMX process running on the host. On ESXi, exploitation stays within the sandbox. However, on Workstation and Fusion, this could lead to code execution on the machine.

CVE-2024-22254: An out-of-bounds write vulnerability in ESXi rated important at 7.9. An attacker with VMX process privileges can trigger an out-of-bounds write leading to a sandbox escape.

CVE-2024-22255: An information disclosure vulnerability rated important at 7.9 in the UHCI USB controller. An attacker with administrative access to a virtual machine can leak memory from the vmx process.  

Impact and Products Affected

Two of the four vulnerabilities could potentially allow an attacker to execute code as the VMX process of the virtual machine. The products affected include:

  • VMware ESXi
  • VMware Workstation Pro / Player (Workstation)
  • VMware Fusion Pro / Fusion (Fusion)
  • VMware Cloud Foundation (Cloud Foundation)

Solutions

For workarounds and patch details, refer to the VMWare advisory. All fixed versions (including the EOL ones) can be found in the response matrix.

You can install these patches using SanerNow. SanerNow Vulnerability Management, Risk Prioritization, and Patch Management detect and automatically fix vulnerabilities with risk-based remediation. With SanerNow, you can keep your systems updated and secure.

Have any questions on how to fix these CVEs specific to your IT? Let’s discuss.

JOIN SECPOD COMMUNITY

Featured Posts

Open Root-Level RCE Flaw in Cisco Nexus 9000 Series Switches Exposes Networks to Complete Compromise — CVE-2026-20212
Root-Level RCE Flaw in Cisco Nexus 9000 Series Switches Exposes Networks to Complete Compromise — CVE-2026-20212

CVE Research

Root-Level RCE Flaw in Cisco Nexus 9000 Series Switches Exposes Networks to Complete Compromise — CVE-2026-20212

CVE-2026-20212 is a critical vulnerability in Cisco Nexus 9000 Series Switches that use Silicon One ASICs. It allows an unauthenticated remote attacker to execute code with root privileges by sending crafted input to TCP ports 43210 and 43211, which are reachable in the default Layer 3 VRF. Exploitation can also crash the S1HAL process and force a device reload. This article covers how the vulnerability works, the affected product identifiers, its potential impact, available workarounds, and how to identify fixed software using the Cisco Software Checker.

Sep 4, 2026

Open SonicWall SMA 1000 Under Active Attack: Two Zero-Days Enable SSRF and Remote Code Execution
SonicWall SMA 1000 Under Active Attack: Two Zero-Days Enable SSRF and Remote Code Execution

CVE Research

SonicWall SMA 1000 Under Active Attack: Two Zero-Days Enable SSRF and Remote Code Execution

Sep 3, 2026

Open Introducing SecPod VEX Studio: Guided Vulnerability Exploitability Assessment for Open-Source Maintainers
Secpod_VEX_Studio For Open-Source Vulnerability Management

CVE Research

Introducing SecPod VEX Studio: Guided Vulnerability Exploitability Assessment for Open-Source Maintainers

A human-guided path from SBOM and vulnerability data to reviewable OpenVEX statements

Sep 2, 2026

Open Inside the PaperCut Zero-Day Attack Chain: Auth Bypass to Code Execution
Inside the PaperCut Zero-Day Attack Chain: Auth Bypass to Code Execution

CVE Research

Inside the PaperCut Zero-Day Attack Chain: Auth Bypass to Code Execution

Sep 1, 2026

VMWare Catches New Critical ESXi Sandbox Escape Bugs | SecPod