CVE-2024-22273: VMware Cloud Foundation
High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.
The storage controllers on VMware ESXi, Workstation, and Fusion have out-of-bounds read/write vulnerability. A malicious actor with access to a virtual machine with storage controllers enabled may exploit this issue to create a denial of service condition or execute code on the hypervisor from a virtual machine in conjunction with other issues.
Affected products
- VMware Cloud Foundation: from 4.0, before 5.1.1 (fixed in 5.1.1)
- VMware ESXi: version 7.0 only; version 8.0 only
- VMware Fusion: from 13.0.0, before 13.5.1 (fixed in 13.5.1)
- VMware Workstation: from 17.0.0, before 17.5.1 (fixed in 17.5.1)
Published 2024-05-21. Last modified 2026-06-17.