Vulnerability Details CVE-2024-22251
VMware Workstation and Fusion contain an out-of-bounds read vulnerability in the USB CCID (chip card interface device). A malicious actor with local administrative privileges on a virtual machine may trigger an out-of-bounds read leading to information disclosure.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 13.2%
CVSS Severity
CVSS v3 Score 5.9
Products affected by CVE-2024-22251
-
cpe:2.3:a:vmware:fusion:13.0.0
-
cpe:2.3:a:vmware:fusion:13.0.1
-
cpe:2.3:a:vmware:fusion:13.0.2
-
cpe:2.3:a:vmware:fusion:13.5
-
cpe:2.3:a:vmware:workstation:17.0
-
cpe:2.3:a:vmware:workstation:17.0.0
-
cpe:2.3:a:vmware:workstation:17.0.1
-
cpe:2.3:a:vmware:workstation:17.0.2
-
cpe:2.3:a:vmware:workstation:17.5.0
-