VID |
23344 |
Severity |
40 |
Port |
139,445 |
Protocol |
TCP |
Class |
SMB |
Detailed Description |
The version of VMware Workstation installed on the remote host is 17.0.x prior to 17.5.2. It is, therefore, affected by multiple vulnerabilities.
- VMware Workstation and Fusion contain a use-after-free vulnerability in the vbluetooth device. (CVE-2024-22267) - VMware Workstation contains a heap buffer-overflow vulnerability in the Shader functionality. (CVE-2024-22268) - VMware Workstation and Fusion contain an information disclosure vulnerability in the vbluetooth device. (CVE-2024-22269) - VMware Workstation and Fusion contain an information disclosure vulnerability in the Host Guest File Sharing (HGFS) functionality. (CVE-2024-22270)
* References: https://www.vmware.com/security/advisories/VMSA-2024-0010.html
* Platforms Affected: VMware Workstation prior to 17.5.2 Linux Any version Microsoft Windows Any version |
Recommendation |
Upgrade to the latest versions of the affected applications(VMware Workstation 17.5.2 or later) available from the VMware Download Web site at http://www.vmware.com/download/ |
Related URL |
CVE-2024-22267,CVE-2024-22268,CVE-2024-22269,CVE-2024-22270 (CVE) |
Related URL |
105986 (SecurityFocus) |
Related URL |
(ISS) |
|