VMware released security updates to address a critical-severity vulnerability impacting ESXi, Workstation, Fusion, and Cloud Foundation, and a critical-severity command injection flaw affecting vRealize Network Insight.
The VMware ESXi heap out-of-bounds write vulnerability is tracked as CVE-2022-31705 and has received a CVSS v3 severity rating of 9.3.
“A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine’s VMX process running on the host,” mentions the security advisory.
VMware has released step-by-step instructions on how to apply the workaround on a VMware ESXi virtual machine, which also applies to the Cloud Foundation suite.
On a separate security bulletin, VMware gives details about CVE-2022-31702, a critical severity vulnerability that allows command injection in the vRNI REST API of vRealize Network Insight versions 6.2 to 6.7.
VMware vRealize Network Insight 6.8.0 is not affected by these vulnerabilities.