Vulnerability Database

309,961

Total vulnerabilities in the database

CVE-2024-22255

VMware ESXi, Workstation, and Fusion contain an information disclosure vulnerability in the UHCI USB controller. A malicious actor with administrative access to a virtual machine may be able to exploit this issue to leak memory from the vmx process.  

  • Published: Mar 5, 2024
  • Updated: Nov 16, 2025
  • CVE: CVE-2024-22255
  • Severity: High
  • Exploit:

CVSS v3:

  • Severity: High
  • Score: 7.1
  • AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N

CWEs:

Software From Fixed in
vmware / esxi 7.0-update_1 7.0-update_1.x
vmware / esxi 7.0-update_1a 7.0-update_1a.x
vmware / esxi 7.0-update_1b 7.0-update_1b.x
vmware / esxi 7.0 7.0.x
vmware / esxi 7.0.0-b 7.0.0-b.x
vmware / esxi 7.0-update_2 7.0-update_2.x
vmware / esxi 7.0-update_1c 7.0-update_1c.x
vmware / esxi 7.0-update_1d 7.0-update_1d.x
vmware / esxi 7.0-update_1e 7.0-update_1e.x
vmware / esxi 7.0-update_2a 7.0-update_2a.x
vmware / esxi 7.0-update_2c 7.0-update_2c.x
vmware / esxi 7.0-update_2d 7.0-update_2d.x
vmware / esxi 7.0-update_2e 7.0-update_2e.x
vmware / esxi 7.0-update_3 7.0-update_3.x
vmware / esxi 7.0-update_3c 7.0-update_3c.x
vmware / esxi 7.0-update_3d 7.0-update_3d.x
vmware / esxi 7.0-update_3e 7.0-update_3e.x
vmware / esxi 7.0-update_3g 7.0-update_3g.x
vmware / workstation 17.0.0 17.5.1
vmware / esxi 7.0-update_3f 7.0-update_3f.x
vmware / esxi 7.0-update_3i 7.0-update_3i.x
vmware / esxi 7.0-update_3j 7.0-update_3j.x
vmware / esxi 7.0-update_3k 7.0-update_3k.x
vmware / esxi 7.0-update_3l 7.0-update_3l.x
vmware / esxi 7.0-update_3m 7.0-update_3m.x
vmware / esxi 7.0-update_3n 7.0-update_3n.x
vmware / esxi 7.0-update_3o 7.0-update_3o.x
vmware / esxi 8.0 8.0.x
vmware / esxi 8.0-a 8.0-a.x
vmware / esxi 8.0-b 8.0-b.x
vmware / esxi 8.0-c 8.0-c.x
vmware / esxi 8.0-update_1 8.0-update_1.x
vmware / esxi 8.0-update_1a 8.0-update_1a.x
vmware / esxi 8.0-update_1c 8.0-update_1c.x
vmware / esxi 8.0-update_2 8.0-update_2.x
vmware / cloud_foundation 4.0 5.0.x
vmware / fusion 13.0.0 13.5.1