VMware fixed critical VM Escape bug demonstrated at Geekpwn hacking contest
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2022-31702 | vRealize Network Insight (vRNI) contains a command injection vulnerability present in the vRNI REST API. vRealize Network Insight (vRNI) contains a command injection vulnerability present in the vRNI REST API. A malicious actor with network access to the vRNI REST API can execute commands without authentication. NVD description · AI analysis pending | 9.8 | 2% |
| — | ||
| CVE-2022-31703 | The vRealize Log Insight contains a Directory Traversal Vulnerability. The vRealize Log Insight contains a Directory Traversal Vulnerability. An unauthenticated, malicious actor can inject files into the operating system of an impacted appliance which can result in remote code execution. NVD description · AI analysis pending | 7.5 | 2% |
| — | ||
| CVE-2022-31705 | VMware ESXi, Workstation, and Fusion contain a heap out-of-bounds write vulnerability in the USB 2.0 controller (EHCI). VMware ESXi, Workstation, and Fusion contain a heap out-of-bounds write vulnerability in the USB 2.0 controller (EHCI). A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host. On ESXi, the exploitation is contained within the VMX sandbox whereas, on Workstation and Fusion, this may lead to code execution on the machine where Workstation or Fusion is installed. NVD description · AI analysis pending | 8.2 | 2% |
| — |
Full article368 words · extracted from securityaffairs.com · click to collapse
Pierluigi Paganini
December 14, 2022

VMware fixed three flaws in multiple products, including a virtual machine escape issue exploited at the GeekPwn 2022 hacking competition.
VMware addressed three vulnerabilities in multiple products, including a virtual machine escape flaw, tracked as CVE-2022-31705, that was exploited at the GeekPwn 2022 hacking competition.
A working exploit for the CVE-2022-31705 vulnerability was demonstrated by Ant Security researcher Yuhao Jiang during the Geekpwn, a hacking contest run by the Tencent Keen Security Lab.
Here is my demo of the VM escape exploit on the latest version of VMware Fusion along with ESXi and Workstation. It was used to participate in GeekPwn 2022 and won the championship. pic.twitter.com/Ze2rtCVAsv
— Danis Jiang (@danis_jiang) November 14, 2022
The CVE-2022-31705 vulnerability (CVSSv3 base score of 9.3) is a heap out-of-bounds write issue in the USB 2.0 controller (EHCI).
“VMware ESXi, Workstation, and Fusion contain a heap out-of-bounds write vulnerability in the USB 2.0 controller (EHCI)” reads the advisory published by the virtualization giant. “A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine’s VMX process running on the host. On ESXi, the exploitation is contained within the VMX sandbox whereas, on Workstation and Fusion, this may lead to code execution on the machine where Workstation or Fusion is installed.”
The company also addressed a command injection and directory traversal security vulnerabilities, respectively tracked as CVE-2022-31702 and CVE-2022-31703, impacting the VMware vRealize Network Insight (vRNI) solution. Below are the details for the flaws:
- VMware vRealize Network Insight (vRNI) command injection vulnerability (CVE-2022-31702) – “vRealize Network Insight (vRNI) contains a command injection vulnerability present in the vRNI REST API.” states the advisory. “A malicious actor with network access to the vRNI REST API can execute commands without authentication.”
- VMware vRealize Network Insight (vRNI) contains a directory traversal vulnerability (CVE-2022-31703) – “vRealize Network Insight (vRNI) directory traversal vulnerability in vRNI REST API.” reads the advisory. “A malicious actor with network access to the vRNI REST API can read arbitrary files from the server.”
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
| [adrotate banner=”9″] | [adrotate banner=”12″] |
(SecurityAffairs – hacking, VMware)
[adrotate banner=”5″]
[adrotate banner=”13″]
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/139616/security/vmware-vm-escape-flaw-geekpwn.html