Vulnerability Details CVE-2021-22043
VMware ESXi contains a TOCTOU (Time-of-check Time-of-use) vulnerability that exists in the way temporary files are handled. A malicious actor with access to settingsd, may exploit this issue to escalate their privileges by writing arbitrary files.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.004
EPSS Ranking 61.9%
CVSS Severity
CVSS v3 Score 7.5
CVSS v2 Score 6.0
Products affected by CVE-2021-22043
-
cpe:2.3:a:vmware:fusion:-
-
cpe:2.3:a:vmware:fusion:1.1.1
-
cpe:2.3:a:vmware:fusion:3.1
-
cpe:2.3:a:vmware:fusion:3.1.1
-
cpe:2.3:a:vmware:fusion:3.1.2
-
cpe:2.3:a:vmware:fusion:4.0
-
cpe:2.3:a:vmware:fusion:4.0.1
-
cpe:2.3:a:vmware:fusion:4.0.2
-
cpe:2.3:a:vmware:fusion:4.1
-
cpe:2.3:a:vmware:fusion:4.1.1
-
cpe:2.3:a:vmware:fusion:4.1.2
-
cpe:2.3:a:vmware:fusion:4.1.3
-
cpe:2.3:a:vmware:fusion:4.1.4
-
cpe:2.3:o:vmware:esxi:7.0