{"id":7448,"date":"2022-01-28T17:58:17","date_gmt":"2022-01-29T00:58:17","guid":{"rendered":"https:\/\/webdev.securin.xyz\/?p=7448"},"modified":"2023-04-05T12:35:23","modified_gmt":"2023-04-05T19:35:23","slug":"patch-now-vmware-fixed-cve-2021-22045-heap-overflow-vulnerability","status":"publish","type":"post","link":"https:\/\/webdev.securin.xyz\/articles\/patch-now-vmware-fixed-cve-2021-22045-heap-overflow-vulnerability\/","title":{"rendered":"Patch Now: Vmware Fixed CVE-2021-22045 Heap-Overflow Vulnerability"},"content":{"rendered":"
On January 04, 2022, VMware has published security fixes for its Workstation, Fusion, and ESXi products to address a heap-overflow vulnerability identified as CVE-2021-22045. Attackers on various VMware platforms can exploit a virtual CD-ROM drive to execute malicious code in the hypervisor; however, not all products have been fixed as of yet.<\/p>\n
\nUsers of ESXi version 7 are still waiting for a complete fix for this high-severity heap-overflow security flaw, in the meantime Cloud Foundation, Fusion, and Workstation users install the patches straight away.<\/p>\n<\/blockquote>\n
The CVSS v3 base score for this vulnerability is 7.8, which is classified as “high” in severity. A heap overflow is a memory issue that can corrupt data or introduce unexpected behavior into any process accessing the affected memory area – in some cases resulting in remote code execution (RCE) and Denial of Service (DoS).<\/p>\n