VMware ESX, Workstation, and Fusion contain an out-of-bounds read vulnerability. A malicious actor with VM deployment privileges could trigger an out-of-bounds read, potentially leading to information disclosure or more likely a Denial-of-Service (DoS) condition of the host process. On Workstation and Fusion, the impact of this vulnerability is restricted to information disclosure.
| Vendor | Product | Versions |
|---|---|---|
| VMware | Cloud Foundation | 9.1.x.x, 9.0.x.x, 5.x, 9.1.x.x, 9.0.x.x, 9.1.x.x, 9.0.x.x, 8.0, 25H2, 25H2, 5.1.x, 5.0.x |
Downstream vendors/products affected by this vulnerability
| Vendor | Product | Source | Confidence |
|---|---|---|---|
| vmware | esx | mitre_affected | 90% |
| vmware | workstation | mitre_affected | 90% |
| vmware | fusion | mitre_affected | 90% |
| vmware | telco cloud | mitre_affected | 90% |
| vmware | vsphere foundation | mitre_affected | 90% |