VMware ESX contains an out-of-bounds write vulnerability in the VMXNET3 virtual network adapter. A malicious actor with local administrative privileges on a virtual machine with VMXNET3 virtual network adapter may exploit this issue to execute code on the host. Non VMXNET3 virtual adapters are not affected by this issue.
| Vendor | Product | Versions |
|---|---|---|
| VMware | Cloud Foundation | 9.1.x.x, 9.0.x.x, 5.x, 9.1.x.x, 9.0.x.x, 9.1.x.x, 9.0.x.x, 8.0, 5.1.x, 5.0.x |
Downstream vendors/products affected by this vulnerability
| Vendor | Product | Source | Confidence |
|---|---|---|---|
| vmware | vsphere foundation | mitre_affected | 90% |
| vmware | esx | mitre_affected | 90% |
| vmware | telco cloud | mitre_affected | 90% |